Go to the documentation of this file.
24 #ifndef MBEDTLS_CONFIG_ADJUST_LEGACY_CRYPTO_H
25 #define MBEDTLS_CONFIG_ADJUST_LEGACY_CRYPTO_H
27 #if !defined(MBEDTLS_CONFIG_FILES_READ)
28 #error "Do not include mbedtls/config_adjust_*.h manually! This can lead to problems, " \
29 "up to and including runtime errors such as buffer overflows. " \
30 "If you're trying to fix a complaint from check_config.h, just remove " \
31 "it from your configuration file: since Mbed TLS 3.0, it is included " \
32 "automatically at the right point."
40 #if defined(__MINGW32__) || (defined(_MSC_VER) && _MSC_VER <= 1900)
41 #if !defined(MBEDTLS_PLATFORM_SNPRINTF_ALT) && \
42 !defined(MBEDTLS_PLATFORM_SNPRINTF_MACRO)
43 #define MBEDTLS_PLATFORM_SNPRINTF_ALT
45 #if !defined(MBEDTLS_PLATFORM_VSNPRINTF_ALT) && \
46 !defined(MBEDTLS_PLATFORM_VSNPRINTF_MACRO)
47 #define MBEDTLS_PLATFORM_VSNPRINTF_ALT
56 #if defined(MBEDTLS_NO_PLATFORM_ENTROPY)
57 #define MBEDTLS_PLATFORM_ENTROPY_ENABLED 0
59 #define MBEDTLS_PLATFORM_ENTROPY_ENABLED 1
61 #if defined(MBEDTLS_ENTROPY_HARDWARE_ALT)
62 #define MBEDTLS_ENTROPY_HARDWARE_ALT_DEFINED 1
64 #define MBEDTLS_ENTROPY_HARDWARE_ALT_DEFINED 0
67 #define MBEDTLS_ENTROPY_TRUE_SOURCES ( \
68 MBEDTLS_ENTROPY_HARDWARE_ALT_DEFINED + \
69 MBEDTLS_PLATFORM_ENTROPY_ENABLED + \
78 #if defined(MBEDTLS_ENTROPY_NV_SEED)
79 #define MBEDTLS_ENTROPY_HAVE_SOURCES (MBEDTLS_ENTROPY_TRUE_SOURCES + 1)
80 #elif MBEDTLS_ENTROPY_TRUE_SOURCES != 0
81 #define MBEDTLS_ENTROPY_HAVE_SOURCES MBEDTLS_ENTROPY_TRUE_SOURCES
83 #undef MBEDTLS_ENTROPY_HAVE_SOURCES
88 #if MBEDTLS_ENTROPY_TRUE_SOURCES > 0
89 #define MBEDTLS_ENTROPY_HAVE_TRUE_SOURCES
91 #undef MBEDTLS_ENTROPY_HAVE_TRUE_SOURCES
97 #if defined(MBEDTLS_PSA_CRYPTO_C)
98 #define MBEDTLS_PSA_CRYPTO_CLIENT
103 #if defined(MBEDTLS_PSA_CRYPTO_C) && \
104 (defined(MBEDTLS_PSA_BUILTIN_ALG_STREAM_CIPHER) || \
105 defined(MBEDTLS_PSA_BUILTIN_ALG_CTR) || \
106 defined(MBEDTLS_PSA_BUILTIN_ALG_CFB) || \
107 defined(MBEDTLS_PSA_BUILTIN_ALG_OFB) || \
108 defined(MBEDTLS_PSA_BUILTIN_ALG_ECB_NO_PADDING) || \
109 defined(MBEDTLS_PSA_BUILTIN_ALG_CBC_NO_PADDING) || \
110 defined(MBEDTLS_PSA_BUILTIN_ALG_CBC_PKCS7) || \
111 defined(MBEDTLS_PSA_BUILTIN_ALG_CCM_STAR_NO_TAG) || \
112 defined(MBEDTLS_PSA_BUILTIN_ALG_CMAC))
113 #define MBEDTLS_CIPHER_C
119 #if defined(MBEDTLS_MD_C)
120 #define MBEDTLS_MD_LIGHT
126 #if defined(MBEDTLS_ECJPAKE_C) || \
127 defined(MBEDTLS_PEM_PARSE_C) || \
128 defined(MBEDTLS_ENTROPY_C) || \
129 defined(MBEDTLS_PK_C) || \
130 defined(MBEDTLS_PKCS12_C) || \
131 defined(MBEDTLS_RSA_C) || \
132 defined(MBEDTLS_SSL_TLS_C) || \
133 defined(MBEDTLS_X509_USE_C) || \
134 defined(MBEDTLS_X509_CREATE_C)
135 #define MBEDTLS_MD_LIGHT
138 #if defined(MBEDTLS_MD_LIGHT)
154 #if defined(MBEDTLS_PSA_CRYPTO_C)
156 #if defined(MBEDTLS_PSA_ACCEL_ALG_MD5)
157 #define MBEDTLS_MD_CAN_MD5
158 #define MBEDTLS_MD_MD5_VIA_PSA
159 #define MBEDTLS_MD_SOME_PSA
161 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA_1)
162 #define MBEDTLS_MD_CAN_SHA1
163 #define MBEDTLS_MD_SHA1_VIA_PSA
164 #define MBEDTLS_MD_SOME_PSA
166 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA_224)
167 #define MBEDTLS_MD_CAN_SHA224
168 #define MBEDTLS_MD_SHA224_VIA_PSA
169 #define MBEDTLS_MD_SOME_PSA
171 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA_256)
172 #define MBEDTLS_MD_CAN_SHA256
173 #define MBEDTLS_MD_SHA256_VIA_PSA
174 #define MBEDTLS_MD_SOME_PSA
176 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA_384)
177 #define MBEDTLS_MD_CAN_SHA384
178 #define MBEDTLS_MD_SHA384_VIA_PSA
179 #define MBEDTLS_MD_SOME_PSA
181 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA_512)
182 #define MBEDTLS_MD_CAN_SHA512
183 #define MBEDTLS_MD_SHA512_VIA_PSA
184 #define MBEDTLS_MD_SOME_PSA
186 #if defined(MBEDTLS_PSA_ACCEL_ALG_RIPEMD160)
187 #define MBEDTLS_MD_CAN_RIPEMD160
188 #define MBEDTLS_MD_RIPEMD160_VIA_PSA
189 #define MBEDTLS_MD_SOME_PSA
191 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA3_224)
192 #define MBEDTLS_MD_CAN_SHA3_224
193 #define MBEDTLS_MD_SHA3_224_VIA_PSA
194 #define MBEDTLS_MD_SOME_PSA
196 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA3_256)
197 #define MBEDTLS_MD_CAN_SHA3_256
198 #define MBEDTLS_MD_SHA3_256_VIA_PSA
199 #define MBEDTLS_MD_SOME_PSA
201 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA3_384)
202 #define MBEDTLS_MD_CAN_SHA3_384
203 #define MBEDTLS_MD_SHA3_384_VIA_PSA
204 #define MBEDTLS_MD_SOME_PSA
206 #if defined(MBEDTLS_PSA_ACCEL_ALG_SHA3_512)
207 #define MBEDTLS_MD_CAN_SHA3_512
208 #define MBEDTLS_MD_SHA3_512_VIA_PSA
209 #define MBEDTLS_MD_SOME_PSA
212 #elif defined(MBEDTLS_PSA_CRYPTO_CLIENT)
214 #if defined(PSA_WANT_ALG_MD5)
215 #define MBEDTLS_MD_CAN_MD5
216 #define MBEDTLS_MD_MD5_VIA_PSA
217 #define MBEDTLS_MD_SOME_PSA
219 #if defined(PSA_WANT_ALG_SHA_1)
220 #define MBEDTLS_MD_CAN_SHA1
221 #define MBEDTLS_MD_SHA1_VIA_PSA
222 #define MBEDTLS_MD_SOME_PSA
224 #if defined(PSA_WANT_ALG_SHA_224)
225 #define MBEDTLS_MD_CAN_SHA224
226 #define MBEDTLS_MD_SHA224_VIA_PSA
227 #define MBEDTLS_MD_SOME_PSA
229 #if defined(PSA_WANT_ALG_SHA_256)
230 #define MBEDTLS_MD_CAN_SHA256
231 #define MBEDTLS_MD_SHA256_VIA_PSA
232 #define MBEDTLS_MD_SOME_PSA
234 #if defined(PSA_WANT_ALG_SHA_384)
235 #define MBEDTLS_MD_CAN_SHA384
236 #define MBEDTLS_MD_SHA384_VIA_PSA
237 #define MBEDTLS_MD_SOME_PSA
239 #if defined(PSA_WANT_ALG_SHA_512)
240 #define MBEDTLS_MD_CAN_SHA512
241 #define MBEDTLS_MD_SHA512_VIA_PSA
242 #define MBEDTLS_MD_SOME_PSA
244 #if defined(PSA_WANT_ALG_RIPEMD160)
245 #define MBEDTLS_MD_CAN_RIPEMD160
246 #define MBEDTLS_MD_RIPEMD160_VIA_PSA
247 #define MBEDTLS_MD_SOME_PSA
249 #if defined(PSA_WANT_ALG_SHA3_224)
250 #define MBEDTLS_MD_CAN_SHA3_224
251 #define MBEDTLS_MD_SHA3_224_VIA_PSA
252 #define MBEDTLS_MD_SOME_PSA
254 #if defined(PSA_WANT_ALG_SHA3_256)
255 #define MBEDTLS_MD_CAN_SHA3_256
256 #define MBEDTLS_MD_SHA3_256_VIA_PSA
257 #define MBEDTLS_MD_SOME_PSA
259 #if defined(PSA_WANT_ALG_SHA3_384)
260 #define MBEDTLS_MD_CAN_SHA3_384
261 #define MBEDTLS_MD_SHA3_384_VIA_PSA
262 #define MBEDTLS_MD_SOME_PSA
264 #if defined(PSA_WANT_ALG_SHA3_512)
265 #define MBEDTLS_MD_CAN_SHA3_512
266 #define MBEDTLS_MD_SHA3_512_VIA_PSA
267 #define MBEDTLS_MD_SOME_PSA
273 #if defined(MBEDTLS_MD5_C)
274 #define MBEDTLS_MD_CAN_MD5
275 #define MBEDTLS_MD_SOME_LEGACY
277 #if defined(MBEDTLS_SHA1_C)
278 #define MBEDTLS_MD_CAN_SHA1
279 #define MBEDTLS_MD_SOME_LEGACY
281 #if defined(MBEDTLS_SHA224_C)
282 #define MBEDTLS_MD_CAN_SHA224
283 #define MBEDTLS_MD_SOME_LEGACY
285 #if defined(MBEDTLS_SHA256_C)
286 #define MBEDTLS_MD_CAN_SHA256
287 #define MBEDTLS_MD_SOME_LEGACY
289 #if defined(MBEDTLS_SHA384_C)
290 #define MBEDTLS_MD_CAN_SHA384
291 #define MBEDTLS_MD_SOME_LEGACY
293 #if defined(MBEDTLS_SHA512_C)
294 #define MBEDTLS_MD_CAN_SHA512
295 #define MBEDTLS_MD_SOME_LEGACY
297 #if defined(MBEDTLS_SHA3_C)
298 #define MBEDTLS_MD_CAN_SHA3_224
299 #define MBEDTLS_MD_CAN_SHA3_256
300 #define MBEDTLS_MD_CAN_SHA3_384
301 #define MBEDTLS_MD_CAN_SHA3_512
302 #define MBEDTLS_MD_SOME_LEGACY
304 #if defined(MBEDTLS_RIPEMD160_C)
305 #define MBEDTLS_MD_CAN_RIPEMD160
306 #define MBEDTLS_MD_SOME_LEGACY
326 #if defined(MBEDTLS_PSA_CRYPTO_C)
327 #if defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_AES)
328 #define MBEDTLS_BLOCK_CIPHER_AES_VIA_PSA
329 #define MBEDTLS_BLOCK_CIPHER_SOME_PSA
331 #if defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_ARIA)
332 #define MBEDTLS_BLOCK_CIPHER_ARIA_VIA_PSA
333 #define MBEDTLS_BLOCK_CIPHER_SOME_PSA
335 #if defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_CAMELLIA)
336 #define MBEDTLS_BLOCK_CIPHER_CAMELLIA_VIA_PSA
337 #define MBEDTLS_BLOCK_CIPHER_SOME_PSA
341 #if defined(MBEDTLS_AES_C)
342 #define MBEDTLS_BLOCK_CIPHER_AES_VIA_LEGACY
344 #if defined(MBEDTLS_ARIA_C)
345 #define MBEDTLS_BLOCK_CIPHER_ARIA_VIA_LEGACY
347 #if defined(MBEDTLS_CAMELLIA_C)
348 #define MBEDTLS_BLOCK_CIPHER_CAMELLIA_VIA_LEGACY
353 #if defined(MBEDTLS_BLOCK_CIPHER_AES_VIA_PSA) || \
354 defined(MBEDTLS_BLOCK_CIPHER_AES_VIA_LEGACY)
355 #define MBEDTLS_BLOCK_CIPHER_CAN_AES
357 #if defined(MBEDTLS_BLOCK_CIPHER_ARIA_VIA_PSA) || \
358 defined(MBEDTLS_BLOCK_CIPHER_ARIA_VIA_LEGACY)
359 #define MBEDTLS_BLOCK_CIPHER_CAN_ARIA
361 #if defined(MBEDTLS_BLOCK_CIPHER_CAMELLIA_VIA_PSA) || \
362 defined(MBEDTLS_BLOCK_CIPHER_CAMELLIA_VIA_LEGACY)
363 #define MBEDTLS_BLOCK_CIPHER_CAN_CAMELLIA
372 #if (defined(MBEDTLS_GCM_C) || defined(MBEDTLS_CCM_C)) && \
373 (!defined(MBEDTLS_CIPHER_C) || defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA))
374 #define MBEDTLS_BLOCK_CIPHER_C
378 #if (defined(MBEDTLS_CIPHER_C) && defined(MBEDTLS_AES_C)) || \
379 (defined(MBEDTLS_BLOCK_CIPHER_C) && defined(MBEDTLS_BLOCK_CIPHER_CAN_AES))
380 #define MBEDTLS_CCM_GCM_CAN_AES
383 #if (defined(MBEDTLS_CIPHER_C) && defined(MBEDTLS_ARIA_C)) || \
384 (defined(MBEDTLS_BLOCK_CIPHER_C) && defined(MBEDTLS_BLOCK_CIPHER_CAN_ARIA))
385 #define MBEDTLS_CCM_GCM_CAN_ARIA
388 #if (defined(MBEDTLS_CIPHER_C) && defined(MBEDTLS_CAMELLIA_C)) || \
389 (defined(MBEDTLS_BLOCK_CIPHER_C) && defined(MBEDTLS_BLOCK_CIPHER_CAN_CAMELLIA))
390 #define MBEDTLS_CCM_GCM_CAN_CAMELLIA
409 #if defined(MBEDTLS_ECP_C) || \
410 defined(MBEDTLS_PK_PARSE_EC_EXTENDED) || \
411 defined(MBEDTLS_PK_PARSE_EC_COMPRESSED) || \
412 defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE)
413 #define MBEDTLS_ECP_LIGHT
419 #if defined(MBEDTLS_RSA_C)
420 #define MBEDTLS_ASN1_PARSE_C
421 #define MBEDTLS_ASN1_WRITE_C
429 #if defined(MBEDTLS_PK_PARSE_C) && defined(MBEDTLS_ECP_C)
430 #define MBEDTLS_PK_PARSE_EC_COMPRESSED
435 #if (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_ECDH)) || \
436 (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_ECDH_C))
437 #define MBEDTLS_CAN_ECDH
444 #if !defined(MBEDTLS_USE_PSA_CRYPTO)
445 #if defined(MBEDTLS_ECDSA_C)
446 #define MBEDTLS_PK_CAN_ECDSA_SIGN
447 #define MBEDTLS_PK_CAN_ECDSA_VERIFY
450 #if defined(PSA_WANT_ALG_ECDSA)
451 #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC)
452 #define MBEDTLS_PK_CAN_ECDSA_SIGN
454 #if defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY)
455 #define MBEDTLS_PK_CAN_ECDSA_VERIFY
460 #if defined(MBEDTLS_PK_CAN_ECDSA_VERIFY) || defined(MBEDTLS_PK_CAN_ECDSA_SIGN)
461 #define MBEDTLS_PK_CAN_ECDSA_SOME
465 #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED) || defined(PSA_WANT_ECC_SECP_R1_521)
466 #define MBEDTLS_ECP_HAVE_SECP521R1
468 #if defined(MBEDTLS_ECP_DP_BP512R1_ENABLED) || defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
469 #define MBEDTLS_ECP_HAVE_BP512R1
471 #if defined(MBEDTLS_ECP_DP_CURVE448_ENABLED) || defined(PSA_WANT_ECC_MONTGOMERY_448)
472 #define MBEDTLS_ECP_HAVE_CURVE448
474 #if defined(MBEDTLS_ECP_DP_BP384R1_ENABLED) || defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
475 #define MBEDTLS_ECP_HAVE_BP384R1
477 #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED) || defined(PSA_WANT_ECC_SECP_R1_384)
478 #define MBEDTLS_ECP_HAVE_SECP384R1
480 #if defined(MBEDTLS_ECP_DP_BP256R1_ENABLED) || defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
481 #define MBEDTLS_ECP_HAVE_BP256R1
483 #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED) || defined(PSA_WANT_ECC_SECP_K1_256)
484 #define MBEDTLS_ECP_HAVE_SECP256K1
486 #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) || defined(PSA_WANT_ECC_SECP_R1_256)
487 #define MBEDTLS_ECP_HAVE_SECP256R1
489 #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED) || defined(PSA_WANT_ECC_MONTGOMERY_255)
490 #define MBEDTLS_ECP_HAVE_CURVE25519
492 #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) || defined(PSA_WANT_ECC_SECP_K1_224)
493 #define MBEDTLS_ECP_HAVE_SECP224K1
495 #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) || defined(PSA_WANT_ECC_SECP_R1_224)
496 #define MBEDTLS_ECP_HAVE_SECP224R1
498 #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) || defined(PSA_WANT_ECC_SECP_K1_192)
499 #define MBEDTLS_ECP_HAVE_SECP192K1
501 #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED) || defined(PSA_WANT_ECC_SECP_R1_192)
502 #define MBEDTLS_ECP_HAVE_SECP192R1
508 #if defined(MBEDTLS_ECP_C) || \
509 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY))
510 #define MBEDTLS_PK_HAVE_ECC_KEYS
517 #if defined(MBEDTLS_PK_PARSE_C) && defined(MBEDTLS_PKCS5_C) && defined(MBEDTLS_CIPHER_MODE_CBC)
518 #define MBEDTLS_CIPHER_PADDING_PKCS7
523 #if defined(MBEDTLS_SHA256_USE_A64_CRYPTO_IF_PRESENT) && \
524 !defined(MBEDTLS_SHA256_USE_ARMV8_A_CRYPTO_IF_PRESENT)
525 #define MBEDTLS_SHA256_USE_ARMV8_A_CRYPTO_IF_PRESENT
527 #if defined(MBEDTLS_SHA256_USE_A64_CRYPTO_ONLY) && !defined(MBEDTLS_SHA256_USE_ARMV8_A_CRYPTO_ONLY)
528 #define MBEDTLS_SHA256_USE_ARMV8_A_CRYPTO_ONLY
533 #if (defined(MBEDTLS_PSA_CRYPTO_CLIENT) && \
534 (defined(PSA_WANT_ALG_ECDSA) || defined(PSA_WANT_ALG_DETERMINISTIC_ECDSA)))
535 #define MBEDTLS_PSA_UTIL_HAVE_ECDSA
539 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_AES_C)) || \
540 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_KEY_TYPE_AES))
541 #define MBEDTLS_SSL_HAVE_AES
543 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_ARIA_C)) || \
544 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_KEY_TYPE_ARIA))
545 #define MBEDTLS_SSL_HAVE_ARIA
547 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_CAMELLIA_C)) || \
548 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_KEY_TYPE_CAMELLIA))
549 #define MBEDTLS_SSL_HAVE_CAMELLIA
553 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_CIPHER_MODE_CBC)) || \
554 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CBC_NO_PADDING))
555 #define MBEDTLS_SSL_HAVE_CBC
558 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_GCM_C)) || \
559 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_GCM))
560 #define MBEDTLS_SSL_HAVE_GCM
563 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_CCM_C)) || \
564 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CCM))
565 #define MBEDTLS_SSL_HAVE_CCM
568 #if (!defined(MBEDTLS_USE_PSA_CRYPTO) && defined(MBEDTLS_CHACHAPOLY_C)) || \
569 (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CHACHA20_POLY1305))
570 #define MBEDTLS_SSL_HAVE_CHACHAPOLY
573 #if defined(MBEDTLS_SSL_HAVE_GCM) || defined(MBEDTLS_SSL_HAVE_CCM) || \
574 defined(MBEDTLS_SSL_HAVE_CHACHAPOLY)
575 #define MBEDTLS_SSL_HAVE_AEAD