mirror of
https://github.com/openssl/openssl.git
synced 2026-06-06 20:18:09 +00:00
The KDSA instruction can operate in 2 different modes: - Deterministic mode - nonce 'k' is supplied by user. - Non-deterministic mode - nonce 'k' is randomly generated by the instruction itself. When running in the FIPS-Module, do not use KDSA's non-deterministic mode, but generate the nonce 'k' using OpenSSL's random number generator. This ensures that the nonce is generated using a FIPS-approved random number generator. It also makes the FIPS KAT tests work, because those use a pre-setup deterministic random number generator to produce deterministic ECDSA signatures even for non-deterministic mode. Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Reviewed-by: Tomas Mraz <tomas@openssl.org> Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Paul Dale <paul.dale@oracle.com> (Merged from https://github.com/openssl/openssl/pull/29754)