Hello,
> > I may suggest looking in crypto/opensslconf.h header file and
> > check how BIGNUM building is defined. There should be only define:
> > #define THIRTY_TWO_BIT
> > and no SIXTY_FOUR_BIT*
> >
>
> It's properly defined. There goes my wild guess. Any idea why I'm
> failing a "make test"? Here's the dump from it:
>
> testing...
> making all in apps...
> ../util/shlib_wrap.sh ./destest
> Doing cbcm
> Doing ecb
> Doing ede ecb
> Encryption error 1
> k=0000000000000000 p=0000000000000000 o=9295B59BB384736E
> act=20C1680822EB8C78
> Decryption error 1
> k=0000000000000000 p=20C1680822EB8C78 o=0000000000000000
> act=F39B83D60E55703D
..
..
> k=FFFFFFFFFFFFFFFF p=0000000000000000 o=4334CFDA22C486C8
> act=4DFFECE9978D112B
> Decryption error 32
> k=FFFFFFFFFFFFFFFF p=4DFFECE9978D112B o=0000000000000000
> act=380388A8F031A120
> Doing cbc
> Doing desx cbc
> Doing ede cbc
> des_ede3_cbc_encrypt encrypt error
> 0b 95 6b 49 0f ac 2f 99 0e 1e 8a 13 10 c3 4f 6b 53 8d 95 00 76 30 39 a5
> 65 96 da 4e 0a
> 3f e3 01 c9 62 ac 01 d0 22 13 76 3c 1c bd 4c dc 79 96 57 c0 64 ec f5 d4
> 1c 67 38 12 cf
> des_ede3_cbc_encrypt decrypt error
> 37 36 35 34 33 32 31 20 4e 6f 77 20 69 73 20 74 68 65 20 74 69 6d 65 20
> 66 6f 72 20 00
> 27 d8 f1 51 51 39 e8 bd 0f 85 df 52 eb fc 02 ad 4b c6 db 8b 15 22 cf 4f
> 3d 9c 4a bb fa
> Doing pcbc
> Doing cfb8 cfb16 cfb32 cfb48 cfb64 cfb64() ede_cfb64() ede_cfb_encrypt
> encrypt error
> 3DA1276FC0EFF0AB
> 183079A26D4E78B0
> DAE61D7D99B926E9
> done
> Doing ofb
> Doing ofb64
> Doing ede_ofb64
As you can see there are errors in Triple DES routines.
Single DES encription is successful ("Doing ecb") but Triple DES
has errors ("Doing ede ecb" - means Encrypt-Decrypt-Encrypt DES).
In this implementation in triple DES routines first Initial Permutation
is performed on data block, next Encrypt-Decrypt-Encrypt routines are
called (special versions without Initial and Final Permutation) and
at the end Final Permutation is performed on data block and this process
has some errors. In single DES only one Encrypt/Decrypt is performed
and this works good. Because routines in Single/Triple DES are
almost the same I think that there may be some optimization/compiler
problems (not 64-bit problem because DES operates on two 32-bit long
chunks of data "by design").
My proposition is to look at output of command:
$ openssl version -o
options: bn(64,32) md2(int) rc4(idx,int) des(ptr,risc1,16,long)
blowfish(idx)
In this example we have: des(ptr,risc1,16,long) wich means
that we have pointer access to SPTrans table (in the opposite
to index access - "idx"), risc1 optimization (may be risc1/risc2/cisc),
full DES rounds loop unrolling (in the opposite to partial - "4")
and sizeof() DES type DES_LONG is equal to long (in the opposite to
"int").
This options may be controlled with some defines:
-DDES_RISC1
-DDES_RISC2
-DDES_PTR
-DDES_UNROLL
I do not have any better idea like to experiment with this
defines on your system.
According to some source code this combinations may be reasonable:
-DDES_UNROLL
-DDES_RISC1
-DDES_UNROLL -DDES_RISC1
-DDES_RISC2
-DDES_UNROLL -DDES_RISC2
-DDES_PTR
-DDES_UNROLL -DDES_PTR
-DDES_RISC1 -DDES_PTR
-DDES_UNROLL -DDES_RISC1 -DDES_PTR
-DDES_RISC2 -DDES_PTR
-DDES_UNROLL -DDES_RISC2 -DDES_PTR
Next you may look at output of:
$ openssl version -f
and try to lower some compiler optimization options.
Hope this helps.
Best regards,
--
Marek Marcola <[EMAIL PROTECTED]>
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [EMAIL PROTECTED]