Add FIPS mode detection

On FIPS-based systems, DES3 is not used at all, and the default
session type is UDS-based Xvnc rather than TCP-based Xvnc.
This commit is contained in:
matt335672
2025-03-07 12:12:57 +00:00
parent 6979df55ee
commit 39ec7089ac
6 changed files with 71 additions and 10 deletions
+23
View File
@@ -4282,6 +4282,29 @@ g_no_new_privs(void)
#endif
}
/*****************************************************************************/
int
g_fips_mode_enabled(void)
{
int rv = 0;
#if defined (__linux)
char buff[16];
int fd = open("/proc/sys/crypto/fips_enabled", O_RDONLY);
if (fd >= 0)
{
if (read(fd, buff, sizeof(buff)) > 0)
{
rv = (buff[0] != '0');
}
close(fd);
}
#endif
return rv;
}
/*****************************************************************************/
void
g_qsort(void *base, size_t nitems, size_t size,
+9 -1
View File
@@ -428,6 +428,14 @@ int g_tcp4_bind_address(int sck, const char *port, const char *address);
int g_tcp6_socket(void);
int g_tcp6_bind_address(int sck, const char *port, const char *address);
int g_no_new_privs(void);
/**
* Query whether FIPS mode is enabled
*
* In FIPS mode, some cryptographic algorithms are disabled
*
* @return 1 -> FIPS mode enabled, 0 -> FIPS mode disabled or unknown
*/
int g_fips_mode_enabled(void);
void
g_qsort(void *base, size_t nitems, size_t size,
int (*compar)(const void *, const void *));
@@ -461,7 +469,7 @@ g_malloc_nofail(size_t size);
/** Allocate memory with error-checking
*
* @param Number of elementst to allocate
* @param Number of elements to allocate
* @param size Size of each element
* @return Allocated memory
*