1*e7b1675dSTing-Kang Chang // Copyright 2021 Google LLC 2*e7b1675dSTing-Kang Chang // 3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang // 7*e7b1675dSTing-Kang Chang // http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang // 9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang // limitations under the License. 14*e7b1675dSTing-Kang Chang // 15*e7b1675dSTing-Kang Chang /////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang #include "tink/internal/fips_utils.h" 18*e7b1675dSTing-Kang Chang 19*e7b1675dSTing-Kang Chang #include <atomic> 20*e7b1675dSTing-Kang Chang 21*e7b1675dSTing-Kang Chang #include "absl/base/attributes.h" 22*e7b1675dSTing-Kang Chang #include "absl/status/status.h" 23*e7b1675dSTing-Kang Chang #include "openssl/crypto.h" 24*e7b1675dSTing-Kang Chang #include "tink/util/status.h" 25*e7b1675dSTing-Kang Chang 26*e7b1675dSTing-Kang Chang namespace crypto { 27*e7b1675dSTing-Kang Chang namespace tink { 28*e7b1675dSTing-Kang Chang namespace internal { 29*e7b1675dSTing-Kang Chang 30*e7b1675dSTing-Kang Chang #ifdef TINK_USE_ONLY_FIPS 31*e7b1675dSTing-Kang Chang ABSL_CONST_INIT const bool kUseOnlyFips = true; 32*e7b1675dSTing-Kang Chang #else 33*e7b1675dSTing-Kang Chang ABSL_CONST_INIT const bool kUseOnlyFips = false; 34*e7b1675dSTing-Kang Chang #endif 35*e7b1675dSTing-Kang Chang 36*e7b1675dSTing-Kang Chang static std::atomic<bool> is_fips_restricted(false); 37*e7b1675dSTing-Kang Chang SetFipsRestricted()38*e7b1675dSTing-Kang Changvoid SetFipsRestricted() { is_fips_restricted = true; } 39*e7b1675dSTing-Kang Chang UnSetFipsRestricted()40*e7b1675dSTing-Kang Changvoid UnSetFipsRestricted() { is_fips_restricted = false; } 41*e7b1675dSTing-Kang Chang IsFipsModeEnabled()42*e7b1675dSTing-Kang Changbool IsFipsModeEnabled() { return kUseOnlyFips || is_fips_restricted; } 43*e7b1675dSTing-Kang Chang IsFipsEnabledInSsl()44*e7b1675dSTing-Kang Changbool IsFipsEnabledInSsl() { 45*e7b1675dSTing-Kang Chang #ifdef OPENSSL_IS_BORINGSSL 46*e7b1675dSTing-Kang Chang return FIPS_mode(); 47*e7b1675dSTing-Kang Chang #else 48*e7b1675dSTing-Kang Chang return false; 49*e7b1675dSTing-Kang Chang #endif 50*e7b1675dSTing-Kang Chang } 51*e7b1675dSTing-Kang Chang ChecksFipsCompatibility(FipsCompatibility fips_status)52*e7b1675dSTing-Kang Changutil::Status ChecksFipsCompatibility(FipsCompatibility fips_status) { 53*e7b1675dSTing-Kang Chang switch (fips_status) { 54*e7b1675dSTing-Kang Chang case FipsCompatibility::kNotFips: 55*e7b1675dSTing-Kang Chang if (IsFipsModeEnabled()) { 56*e7b1675dSTing-Kang Chang return util::Status(absl::StatusCode::kInternal, 57*e7b1675dSTing-Kang Chang "Primitive not available in FIPS only mode."); 58*e7b1675dSTing-Kang Chang } else { 59*e7b1675dSTing-Kang Chang return util::OkStatus(); 60*e7b1675dSTing-Kang Chang } 61*e7b1675dSTing-Kang Chang case FipsCompatibility::kRequiresBoringCrypto: 62*e7b1675dSTing-Kang Chang if ((IsFipsModeEnabled()) && !IsFipsEnabledInSsl()) { 63*e7b1675dSTing-Kang Chang return util::Status( 64*e7b1675dSTing-Kang Chang absl::StatusCode::kInternal, 65*e7b1675dSTing-Kang Chang "BoringSSL not built with the BoringCrypto module. If you want to " 66*e7b1675dSTing-Kang Chang "use FIPS only mode you have to build BoringSSL in FIPS Mode."); 67*e7b1675dSTing-Kang Chang 68*e7b1675dSTing-Kang Chang } else { 69*e7b1675dSTing-Kang Chang return util::OkStatus(); 70*e7b1675dSTing-Kang Chang } 71*e7b1675dSTing-Kang Chang default: 72*e7b1675dSTing-Kang Chang return util::Status(absl::StatusCode::kInternal, 73*e7b1675dSTing-Kang Chang "Could not determine FIPS status."); 74*e7b1675dSTing-Kang Chang } 75*e7b1675dSTing-Kang Chang } 76*e7b1675dSTing-Kang Chang 77*e7b1675dSTing-Kang Chang } // namespace internal 78*e7b1675dSTing-Kang Chang } // namespace tink 79*e7b1675dSTing-Kang Chang } // namespace crypto 80