Lines Matching +full:fips +full:- +full:140 +full:- +full:2
10 CFLAGS+= -I${libsecureboot_src}/h
12 CFLAGS+= -DHAVE_BR_X509_TIME_CHECK
29 BRSSL_CFLAGS+= -I${BEARSSL}/tools
53 …sed "1,`grep -n .-END ${.ALLSRC:M*.pem} | tail -2 | head -1 | sed 's,:.*,,'`d" ${.ALLSRC:M*.pem} >…
55 # extract 2nd last cert from chain - we use this for self-test
57 sed -n "`grep -n .-BEGIN ${.ALLSRC:M*.pem} | tail -2 | \
58 sed 's,:.*,,' | xargs | (read a b; echo $$a,$$(($$b - 1)))`p" ${.ALLSRC:M*.pem} > ${.TARGET}
62 .-include "local.trust.mk"
77 # needs to be yes for FIPS 140-2 compliance
80 CFLAGS+= -I.
84 CFLAGS+= -DTRUST_ANCHOR_STR=ta_PEM
87 XCFLAGS.vets+= -DVERIFY_CERTS_STR=vc_PEM
96 CFLAGS+= ${VE_HASH_LIST:@H@-DVE_$H_SUPPORT@} \
97 ${VE_SIGNATURE_LIST:@S@-DVE_$S_SUPPORT@}
108 VE_HASH_KAT_STR?= self-tests-are-good
109 VE_HASH_KAT_STR_INPUT= echo -n
110 XCFLAGS.vets+= -DVE_HASH_KAT_STR=\"${VE_HASH_KAT_STR}\"
115 XCFLAGS.vets+= -DVE_HASH_KAT_STR=${VE_HASH_KAT_STR}
117 XCFLAGS.vets+= -DVE_HASH_KAT_STRLEN=${VE_HASH_KAT_STRLEN}
120 # this should be updated occassionally this is 2019-01-01Z
134 BUILD_UTC?= ${${STAT:Ustat} -L -f %m ${BUILD_UTC_FILE}:L:sh}
139 # If we are doing self-tests, we define another arrary vc_PEM
144 # to use as a Known Answer Test (needed for FIPS 140-2)
150 @( echo '/* Autogenerated - DO NOT EDIT!!! */'; echo; \
152 file2c -sx 'static const char ta_PEM[] = {' '};'; \
156 file2c -sx 'static const char vc_PEM[] = {' '};'; echo ) >> ${.TARGET}
163 @( echo '/* Autogenerated - DO NOT EDIT!!! */'; echo; \