On Wed, Jan 29, 2014 at 12:51 AM, Devchandra L Meetei <[email protected]>wrote:

> when I run ./config, The final lines says following things
>
> "Since you've disabled or enabled at least one algorithm, you need to do
> the following before building:
>
>         make depend
> "
> is there any way to check which algo are disabled or
>
Yes. Look at the output after type 'config'. It summarizes the
configuration before the output fills with the other commands. You should
see something like:

Configuring for linux-x86_64
    no-ec_nistp_64_gcc_128 [default]  OPENSSL_NO_EC_NISTP_64_GCC_128 (skip
dir)
    no-gmp          [default]  OPENSSL_NO_GMP (skip dir)
    no-jpake        [experimental] OPENSSL_NO_JPAKE (skip dir)
    no-krb5         [krb5-flavor not specified] OPENSSL_NO_KRB5
    no-md2          [default]  OPENSSL_NO_MD2 (skip dir)
    no-rc5          [default]  OPENSSL_NO_RC5 (skip dir)
    no-rfc3779      [default]  OPENSSL_NO_RFC3779 (skip dir)
    no-sctp         [default]  OPENSSL_NO_SCTP (skip dir)
    no-shared       [default]
    no-store        [experimental] OPENSSL_NO_STORE (skip dir)
    no-zlib         [default]
    no-zlib-dynamic [default]
    ...


> How do I enabled all algo?
>
 With enable-XXX, where XXX is an algorithm that you want to enable.

But it might not be wise to enable some algorithms. For example, there's
usually no reason enable MD2 with 'enable-md2'.

You might want to enable a shared library. Rather than 'enable-shared', all
you need is: './config shared'

You can also disable things you don't need. For example, PSK and SRP are
rarely used, so 'no-psk' and 'no-srp' could be appropriate. (Its a shame
PSK and SRP are not used more often. They provide mutual authentication and
channel binding; and don't do dumb things like separating channel setup for
application authentication and putting a plain text username/password on
the wire in a basic_auth scheme).

Jeff

Reply via email to