Skip to content

Commit 7220e23

Browse files
authored
ci: remove openssl-1.0.2-fips builds (#4995)
1 parent fd41da0 commit 7220e23

File tree

8 files changed

+1
-125
lines changed

8 files changed

+1
-125
lines changed

codebuild/bin/install_default_dependencies.sh

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -43,10 +43,6 @@ if [[ "$S2N_LIBCRYPTO" == "openssl-1.0.2" && ! -d "$OPENSSL_1_0_2_INSTALL_DIR" ]
4343
codebuild/bin/install_openssl_1_0_2.sh "$(mktemp -d)" "$OPENSSL_1_0_2_INSTALL_DIR" "$OS_NAME" > /dev/null ;
4444
fi
4545

46-
# Download and Install the Openssl FIPS module and Openssl 1.0.2-fips
47-
if [[ "$S2N_LIBCRYPTO" == "openssl-1.0.2-fips" ]] && [[ ! -d "$OPENSSL_1_0_2_FIPS_INSTALL_DIR" ]]; then
48-
codebuild/bin/install_openssl_1_0_2_fips.sh "$(mktemp -d)" "$OPENSSL_1_0_2_FIPS_INSTALL_DIR" "$OS_NAME" ; fi
49-
5046
# Download and Install LibreSSL
5147
if [[ "$S2N_LIBCRYPTO" == "libressl" && ! -d "$LIBRESSL_INSTALL_DIR" ]]; then
5248
mkdir -p "$LIBRESSL_INSTALL_DIR"||true

codebuild/bin/install_openssl_1_0_2_fips.sh

Lines changed: 0 additions & 82 deletions
This file was deleted.

codebuild/bin/s2n_set_build_preset.sh

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,10 +49,6 @@ case "${S2N_BUILD_PRESET-default}" in
4949
: "${S2N_LIBCRYPTO:=openssl-1.0.2}"
5050
: "${GCC_VERSION:=6}"
5151
;;
52-
"openssl-1.0.2-fips")
53-
: "${S2N_LIBCRYPTO:=openssl-1.0.2-fips}"
54-
: "${GCC_VERSION:=6}"
55-
;;
5652
"openssl-1.1.1_gcc4-8")
5753
: "${S2N_LIBCRYPTO:=openssl-1.1.1}"
5854
: "${GCC_VERSION:=4.8}"

codebuild/bin/s2n_setup_env.sh

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,6 @@ source codebuild/bin/s2n_set_build_preset.sh
4242
: "${OPENSSL_3_0_INSTALL_DIR:=$TEST_DEPS_DIR/openssl-3.0}"
4343
: "${OPENSSL_1_0_2_INSTALL_DIR:=$TEST_DEPS_DIR/openssl-1.0.2}"
4444
: "${OQS_OPENSSL_1_1_1_INSTALL_DIR:=$TEST_DEPS_DIR/oqs_openssl-1.1.1}"
45-
: "${OPENSSL_1_0_2_FIPS_INSTALL_DIR:=$TEST_DEPS_DIR/openssl-1.0.2-fips}"
4645
: "${BORINGSSL_INSTALL_DIR:=$TEST_DEPS_DIR/boringssl}"
4746
: "${AWSLC_INSTALL_DIR:=$TEST_DEPS_DIR/awslc}"
4847
: "${AWSLC_FIPS_INSTALL_DIR:=$TEST_DEPS_DIR/awslc-fips}"
@@ -99,7 +98,6 @@ export SCAN_BUILD_INSTALL_DIR
9998
export OPENSSL_1_1_1_INSTALL_DIR
10099
export OPENSSL_3_0_INSTALL_DIR
101100
export OPENSSL_1_0_2_INSTALL_DIR
102-
export OPENSSL_1_0_2_FIPS_INSTALL_DIR
103101
export OQS_OPENSSL_1_1_1_INSTALL_DIR
104102
export BORINGSSL_INSTALL_DIR
105103
export AWSLC_INSTALL_DIR
@@ -128,10 +126,6 @@ if [[ -z $S2N_LIBCRYPTO ]]; then export LIBCRYPTO_ROOT=$OPENSSL_1_1_1_INSTALL_DI
128126
if [[ "$S2N_LIBCRYPTO" == "openssl-1.1.1" ]]; then export LIBCRYPTO_ROOT=$OPENSSL_1_1_1_INSTALL_DIR ; fi
129127
if [[ "$S2N_LIBCRYPTO" == "openssl-3.0" ]]; then export LIBCRYPTO_ROOT=$OPENSSL_3_0_INSTALL_DIR ; fi
130128
if [[ "$S2N_LIBCRYPTO" == "openssl-1.0.2" ]]; then export LIBCRYPTO_ROOT=$OPENSSL_1_0_2_INSTALL_DIR ; fi
131-
if [[ "$S2N_LIBCRYPTO" == "openssl-1.0.2-fips" ]]; then
132-
export LIBCRYPTO_ROOT=$OPENSSL_1_0_2_FIPS_INSTALL_DIR ;
133-
export S2N_TEST_IN_FIPS_MODE=1 ;
134-
fi
135129
if [[ "$S2N_LIBCRYPTO" == "boringssl" ]]; then export LIBCRYPTO_ROOT=$BORINGSSL_INSTALL_DIR ; fi
136130

137131
if [[ "$S2N_LIBCRYPTO" == "awslc" ]]; then export LIBCRYPTO_ROOT=$AWSLC_INSTALL_DIR ; fi

codebuild/spec/buildspec_fuzz_batch.yml

Lines changed: 1 addition & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -68,14 +68,4 @@ batch:
6868
privileged-mode: true
6969
variables:
7070
S2N_LIBCRYPTO: openssl-3.0
71-
COMPILER: clang
72-
- identifier: clang_openssl_1_0_2_fips
73-
buildspec: codebuild/spec/buildspec_fuzz.yml
74-
debug-session: true
75-
env:
76-
compute-type: BUILD_GENERAL1_XLARGE
77-
image: 024603541914.dkr.ecr.us-west-2.amazonaws.com/docker:ubuntu22codebuild
78-
privileged-mode: true
79-
variables:
80-
S2N_LIBCRYPTO: openssl-1.0.2-fips
81-
COMPILER: clang
71+
COMPILER: clang

codebuild/spec/buildspec_valgrind.yml

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -50,13 +50,6 @@ batch:
5050
variables:
5151
S2N_LIBCRYPTO: openssl-1.0.2
5252
COMPILER: gcc
53-
- identifier: gcc_openssl_1_0_2_fips
54-
env:
55-
compute-type: BUILD_GENERAL1_LARGE
56-
image: 024603541914.dkr.ecr.us-west-2.amazonaws.com/docker:ubuntu22codebuild
57-
variables:
58-
S2N_LIBCRYPTO: openssl-1.0.2-fips
59-
COMPILER: gcc
6053

6154
phases:
6255
pre_build:

tests/integrationv2/test_sslyze.py

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -227,11 +227,6 @@ def invalid_sslyze_scan_parameters(*args, **kwargs):
227227
sslyze.ScanCommand.SESSION_RENEGOTIATION
228228
]:
229229
return True
230-
# BUG_IN_SSLYZE error for session resumption scan with openssl 1.0.2 fips
231-
if "openssl-1.0.2-fips" in get_flag(S2N_PROVIDER_VERSION):
232-
if scan_command == sslyze.ScanCommand.SESSION_RESUMPTION:
233-
return True
234-
235230
return invalid_test_parameters(*args, **kwargs)
236231

237232

@@ -313,11 +308,6 @@ def invalid_certificate_scans_parameters(*args, **kwargs):
313308
# SSLyze curves scan errors when given ECDSA certs
314309
if "ECDSA" in certificate.name:
315310
return True
316-
317-
# SSLyze curves scan fails to validate with openssl 1.0.2 fips
318-
if "openssl-1.0.2-fips" in get_flag(S2N_PROVIDER_VERSION):
319-
return True
320-
321311
return invalid_test_parameters(*args, **kwargs)
322312

323313

tests/unit/s2n_build_test.c

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,6 @@ S2N_RESULT s2n_check_supported_libcrypto(const char *s2n_libcrypto)
8080
{ .libcrypto = "boringssl", .is_openssl = false },
8181
{ .libcrypto = "libressl", .is_openssl = false },
8282
{ .libcrypto = "openssl-1.0.2", .is_openssl = true },
83-
{ .libcrypto = "openssl-1.0.2-fips", .is_openssl = true },
8483
{ .libcrypto = "openssl-1.1.1", .is_openssl = true },
8584
{ .libcrypto = "openssl-3.0", .is_openssl = true },
8685
};

0 commit comments

Comments
 (0)