blob: c9752d23a32a6a2d3d5f643643edc2c4bd4e12cd [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file config.h
3 *
Paul Bakker37ca75d2011-01-06 12:28:03 +00004 * \brief Configuration options (set of defines)
5 *
Paul Bakker0a597072012-09-25 21:55:46 +00006 * Copyright (C) 2006-2012, Brainspark B.V.
Paul Bakkerb96f1542010-07-18 20:36:00 +00007 *
8 * This file is part of PolarSSL (http://www.polarssl.org)
Paul Bakker84f12b72010-07-18 10:13:04 +00009 * Lead Maintainer: Paul Bakker <polarssl_maintainer at polarssl.org>
Paul Bakkerb96f1542010-07-18 20:36:00 +000010 *
Paul Bakker77b385e2009-07-28 17:23:11 +000011 * All rights reserved.
Paul Bakkere0ccd0a2009-01-04 16:27:10 +000012 *
Paul Bakkere0ccd0a2009-01-04 16:27:10 +000013 * This program is free software; you can redistribute it and/or modify
14 * it under the terms of the GNU General Public License as published by
15 * the Free Software Foundation; either version 2 of the License, or
16 * (at your option) any later version.
17 *
18 * This program is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU General Public License for more details.
22 *
23 * You should have received a copy of the GNU General Public License along
24 * with this program; if not, write to the Free Software Foundation, Inc.,
25 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
26 *
Paul Bakker5121ce52009-01-03 21:22:43 +000027 * This set of compile-time options may be used to enable
28 * or disable features selectively, and reduce the global
29 * memory footprint.
30 */
Paul Bakker40e46942009-01-03 21:51:57 +000031#ifndef POLARSSL_CONFIG_H
32#define POLARSSL_CONFIG_H
Paul Bakker5121ce52009-01-03 21:22:43 +000033
Paul Bakkercce9d772011-11-18 14:26:47 +000034#if defined(_MSC_VER) && !defined(_CRT_SECURE_NO_DEPRECATE)
Paul Bakker5121ce52009-01-03 21:22:43 +000035#define _CRT_SECURE_NO_DEPRECATE 1
36#endif
37
Paul Bakkerf3b86c12011-01-27 15:24:17 +000038/**
Paul Bakker0a62cd12011-01-21 11:00:08 +000039 * \name SECTION: System support
40 *
41 * This section sets system specific settings.
42 * \{
43 */
44
Paul Bakkerf3b86c12011-01-27 15:24:17 +000045/**
46 * \def POLARSSL_HAVE_INT8
Paul Bakker5121ce52009-01-03 21:22:43 +000047 *
Paul Bakkerf3b86c12011-01-27 15:24:17 +000048 * The system uses 8-bit wide native integers.
49 *
50 * Uncomment if native integers are 8-bit wide.
Paul Bakker40e46942009-01-03 21:51:57 +000051#define POLARSSL_HAVE_INT8
Paul Bakker5121ce52009-01-03 21:22:43 +000052 */
53
Paul Bakkerf3b86c12011-01-27 15:24:17 +000054/**
55 * \def POLARSSL_HAVE_INT16
Paul Bakker5121ce52009-01-03 21:22:43 +000056 *
Paul Bakkerf3b86c12011-01-27 15:24:17 +000057 * The system uses 16-bit wide native integers.
58 *
59 * Uncomment if native integers are 16-bit wide.
Paul Bakker40e46942009-01-03 21:51:57 +000060#define POLARSSL_HAVE_INT16
Paul Bakker5121ce52009-01-03 21:22:43 +000061 */
62
Paul Bakkerf3b86c12011-01-27 15:24:17 +000063/**
Paul Bakker62261d62012-10-02 12:19:31 +000064 * \def POLARSSL_HAVE_LONGLONG
Paul Bakker5121ce52009-01-03 21:22:43 +000065 *
Paul Bakker62261d62012-10-02 12:19:31 +000066 * The compiler supports the 'long long' type.
67 * (Only used on 32-bit platforms)
Paul Bakker5121ce52009-01-03 21:22:43 +000068 */
Paul Bakker62261d62012-10-02 12:19:31 +000069#define POLARSSL_HAVE_LONGLONG
Paul Bakker5121ce52009-01-03 21:22:43 +000070
Paul Bakkerf3b86c12011-01-27 15:24:17 +000071/**
72 * \def POLARSSL_HAVE_ASM
73 *
74 * The compiler has support for asm()
75 *
Paul Bakker5121ce52009-01-03 21:22:43 +000076 * Uncomment to enable the use of assembly code.
Paul Bakker68041ec2009-04-19 21:17:55 +000077 *
78 * Requires support for asm() in compiler.
79 *
80 * Used in:
81 * library/timing.c
82 * library/padlock.c
83 * include/polarssl/bn_mul.h
84 *
Paul Bakker5121ce52009-01-03 21:22:43 +000085 */
Paul Bakker40e46942009-01-03 21:51:57 +000086#define POLARSSL_HAVE_ASM
Paul Bakker5121ce52009-01-03 21:22:43 +000087
Paul Bakkerf3b86c12011-01-27 15:24:17 +000088/**
89 * \def POLARSSL_HAVE_SSE2
90 *
Paul Bakkere23c3152012-10-01 14:42:47 +000091 * CPU supports SSE2 instruction set.
Paul Bakkerf3b86c12011-01-27 15:24:17 +000092 *
Paul Bakker5121ce52009-01-03 21:22:43 +000093 * Uncomment if the CPU supports SSE2 (IA-32 specific).
94 *
Paul Bakker40e46942009-01-03 21:51:57 +000095#define POLARSSL_HAVE_SSE2
Paul Bakker5121ce52009-01-03 21:22:43 +000096 */
Paul Bakker0a62cd12011-01-21 11:00:08 +000097/* \} name */
98
Paul Bakkerf3b86c12011-01-27 15:24:17 +000099/**
Paul Bakker0a62cd12011-01-21 11:00:08 +0000100 * \name SECTION: PolarSSL feature support
101 *
102 * This section sets support for features that are or are not needed
103 * within the modules that are enabled.
104 * \{
105 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000106
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000107/**
Paul Bakker15566e42011-04-24 21:19:15 +0000108 * \def POLARSSL_AES_ROM_TABLES
109 *
110 * Store the AES tables in ROM.
111 *
112 * Uncomment this macro to store the AES tables in ROM.
113 *
114#define POLARSSL_AES_ROM_TABLES
115 */
116
117/**
Paul Bakkerb6ecaf52011-04-19 14:29:23 +0000118 * \def POLARSSL_CIPHER_MODE_CFB
119 *
120 * Enable Cipher Feedback mode (CFB) for symmetric ciphers.
121 */
122#define POLARSSL_CIPHER_MODE_CFB
123
124/**
125 * \def POLARSSL_CIPHER_MODE_CTR
126 *
127 * Enable Counter Block Cipher mode (CTR) for symmetric ciphers.
128 */
129#define POLARSSL_CIPHER_MODE_CTR
130
131/**
Paul Bakkerfab5c822012-02-06 16:45:10 +0000132 * \def POLARSSL_CIPHER_NULL_CIPHER
133 *
134 * Enable NULL cipher.
135 * Warning: Only do so when you know what you are doing. This allows for
136 * encryption or channels without any security!
137 *
138 * Requires POLARSSL_ENABLE_WEAK_CIPHERSUITES as well to enable
139 * the following ciphersuites:
Paul Bakker645ce3a2012-10-31 12:32:41 +0000140 * TLS_RSA_WITH_NULL_MD5
141 * TLS_RSA_WITH_NULL_SHA
142 * TLS_RSA_WITH_NULL_SHA256
Paul Bakkerfab5c822012-02-06 16:45:10 +0000143 *
144 * Uncomment this macro to enable the NULL cipher and ciphersuites
145#define POLARSSL_CIPHER_NULL_CIPHER
146 */
147
148/**
Paul Bakkerfab5c822012-02-06 16:45:10 +0000149 * \def POLARSSL_ENABLE_WEAK_CIPHERSUITES
150 *
Paul Bakker645ce3a2012-10-31 12:32:41 +0000151 * Enable weak ciphersuites in SSL / TLS
Paul Bakkerfab5c822012-02-06 16:45:10 +0000152 * Warning: Only do so when you know what you are doing. This allows for
Paul Bakker9a736322012-11-14 12:39:52 +0000153 * channels with virtually no security at all!
Paul Bakkerfab5c822012-02-06 16:45:10 +0000154 *
155 * This enables the following ciphersuites:
Paul Bakker645ce3a2012-10-31 12:32:41 +0000156 * TLS_RSA_WITH_DES_CBC_SHA
157 * TLS_DHE_RSA_WITH_DES_CBC_SHA
Paul Bakkerfab5c822012-02-06 16:45:10 +0000158 *
159 * Uncomment this macro to enable weak ciphersuites
160#define POLARSSL_ENABLE_WEAK_CIPHERSUITES
161 */
162
163/**
Paul Bakker8fe40dc2013-02-02 12:43:08 +0100164 * \def POLARSSL_ERROR_STRERROR_DUMMY
165 *
166 * Enable a dummy error function to make use of error_strerror() in
167 * third party libraries easier.
168 *
169 * Disable if you run into name conflicts and want to really remove the
170 * error_strerror()
171 */
172#define POLARSSL_ERROR_STRERROR_DUMMY
173
174/**
Paul Bakker15566e42011-04-24 21:19:15 +0000175 * \def POLARSSL_GENPRIME
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000176 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000177 * Requires: POLARSSL_BIGNUM_C, POLARSSL_RSA_C
178 *
Paul Bakker15566e42011-04-24 21:19:15 +0000179 * Enable the RSA prime-number generation code.
Paul Bakker5121ce52009-01-03 21:22:43 +0000180 */
Paul Bakker15566e42011-04-24 21:19:15 +0000181#define POLARSSL_GENPRIME
Paul Bakker5121ce52009-01-03 21:22:43 +0000182
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000183/**
Paul Bakker335db3f2011-04-25 15:28:35 +0000184 * \def POLARSSL_FS_IO
185 *
186 * Enable functions that use the filesystem.
187 */
188#define POLARSSL_FS_IO
189
190/**
Paul Bakker43655f42011-12-15 20:11:16 +0000191 * \def POLARSSL_NO_DEFAULT_ENTROPY_SOURCES
192 *
193 * Do not add default entropy sources. These are the platform specific,
194 * hardclock and HAVEGE based poll functions.
195 *
196 * This is useful to have more control over the added entropy sources in an
197 * application.
198 *
199 * Uncomment this macro to prevent loading of default entropy functions.
200#define POLARSSL_NO_DEFAULT_ENTROPY_SOURCES
201 */
202
203/**
Paul Bakker6083fd22011-12-03 21:45:14 +0000204 * \def POLARSSL_NO_PLATFORM_ENTROPY
205 *
206 * Do not use built-in platform entropy functions.
207 * This is useful if your platform does not support
208 * standards like the /dev/urandom or Windows CryptoAPI.
209 *
210 * Uncomment this macro to disable the built-in platform entropy functions.
211#define POLARSSL_NO_PLATFORM_ENTROPY
212 */
213
214/**
Paul Bakker9dcc3222011-03-08 14:16:06 +0000215 * \def POLARSSL_PKCS1_V21
216 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000217 * Requires: POLARSSL_MD_C, POLARSSL_RSA_C
218 *
Paul Bakker9dcc3222011-03-08 14:16:06 +0000219 * Enable support for PKCS#1 v2.1 encoding.
220 * This enables support for RSAES-OAEP and RSASSA-PSS operations.
221 */
222#define POLARSSL_PKCS1_V21
223
224/**
Paul Bakker0216cc12011-03-26 13:40:23 +0000225 * \def POLARSSL_RSA_NO_CRT
226 *
227 * Do not use the Chinese Remainder Theorem for the RSA private operation.
228 *
229 * Uncomment this macro to disable the use of CRT in RSA.
230 *
231#define POLARSSL_RSA_NO_CRT
232 */
Paul Bakker15566e42011-04-24 21:19:15 +0000233
234/**
235 * \def POLARSSL_SELF_TEST
236 *
237 * Enable the checkup functions (*_self_test).
238 */
239#define POLARSSL_SELF_TEST
Paul Bakker5c721f92011-07-27 16:51:09 +0000240
241/**
Paul Bakker40865c82013-01-31 17:13:13 +0100242 * \def POLARSSL_SSL_ALL_ALERT_MESSAGES
243 *
244 * Enable sending of alert messages in case of encountered errors as per RFC.
245 * If you choose not to send the alert messages, PolarSSL can still communicate
246 * with other servers, only debugging of failures is harder.
247 *
248 * The advantage of not sending alert messages, is that no information is given
249 * about reasons for failures thus preventing adversaries of gaining intel.
250 *
251 * Enable sending of all alert messages
252 */
253#define POLARSSL_SSL_ALERT_MESSAGES
254
255/**
Paul Bakkerd66f0702013-01-31 16:57:45 +0100256 * \def POLARSSL_SSL_DEBUG_ALL
257 *
258 * Enable the debug messages in SSL module for all issues.
259 * Debug messages have been disabled in some places to prevent timing
260 * attacks due to (unbalanced) debugging function calls.
261 *
262 * If you need all error reporting you should enable this during debugging,
263 * but remove this for production servers that should log as well.
264 *
265 * Uncomment this macro to report all debug messages on errors introducing
266 * a timing side-channel.
267 *
268#define POLARSSL_SSL_DEBUG_ALL
269 */
270
271/**
Paul Bakker05ef8352012-05-08 09:17:57 +0000272 * \def POLARSSL_SSL_HW_RECORD_ACCEL
273 *
274 * Enable hooking functions in SSL module for hardware acceleration of
275 * individual records.
276 *
277 * Uncomment this macro to enable hooking functions.
278#define POLARSSL_SSL_HW_RECORD_ACCEL
279 */
280
281/**
Paul Bakker5c721f92011-07-27 16:51:09 +0000282 * \def POLARSSL_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
283 *
284 * If set, the X509 parser will not break-off when parsing an X509 certificate
285 * and encountering an unknown critical extension.
286 *
287 * Uncomment to prevent an error.
288 *
289#define POLARSSL_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
290 */
Paul Bakker2770fbd2012-07-03 13:30:23 +0000291
292/**
293 * \def POLARSSL_ZLIB_SUPPORT
294 *
295 * If set, the SSL/TLS module uses ZLIB to support compression and
296 * decompression of packet data.
297 *
298 * Used in: library/ssl_tls.c
299 * library/ssl_cli.c
300 * library/ssl_srv.c
301 *
302 * This feature requires zlib library and headers to be present.
303 *
304 * Uncomment to enable use of ZLIB
305#define POLARSSL_ZLIB_SUPPORT
306 */
Paul Bakker0a62cd12011-01-21 11:00:08 +0000307/* \} name */
308
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000309/**
Paul Bakker0a62cd12011-01-21 11:00:08 +0000310 * \name SECTION: PolarSSL modules
311 *
312 * This section enables or disables entire modules in PolarSSL
313 * \{
314 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000315
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000316/**
317 * \def POLARSSL_AES_C
318 *
319 * Enable the AES block cipher.
320 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000321 * Module: library/aes.c
322 * Caller: library/ssl_tls.c
Paul Bakker96743fc2011-02-12 14:30:57 +0000323 * library/pem.c
Paul Bakker6083fd22011-12-03 21:45:14 +0000324 * library/ctr_drbg.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000325 *
Paul Bakker645ce3a2012-10-31 12:32:41 +0000326 * This module enables the following ciphersuites (if other requisites are
327 * enabled as well):
328 * TLS_RSA_WITH_AES_128_CBC_SHA
329 * TLS_RSA_WITH_AES_256_CBC_SHA
330 * TLS_DHE_RSA_WITH_AES_128_CBC_SHA
331 * TLS_DHE_RSA_WITH_AES_256_CBC_SHA
332 * TLS_RSA_WITH_AES_128_CBC_SHA256
333 * TLS_RSA_WITH_AES_256_CBC_SHA256
334 * TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
335 * TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
336 * TLS_RSA_WITH_AES_128_GCM_SHA256
337 * TLS_RSA_WITH_AES_256_GCM_SHA384
Paul Bakker6deb37e2013-02-19 13:17:08 +0100338 *
339 * PEM uses AES for decrypting encrypted keys.
Paul Bakker5121ce52009-01-03 21:22:43 +0000340 */
Paul Bakker40e46942009-01-03 21:51:57 +0000341#define POLARSSL_AES_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000342
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000343/**
344 * \def POLARSSL_ARC4_C
345 *
346 * Enable the ARCFOUR stream cipher.
347 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000348 * Module: library/arc4.c
349 * Caller: library/ssl_tls.c
350 *
351 * This module enables the following ciphersuites:
Paul Bakker645ce3a2012-10-31 12:32:41 +0000352 * TLS_RSA_WITH_RC4_128_MD5
353 * TLS_RSA_WITH_RC4_128_SHA
Paul Bakker5121ce52009-01-03 21:22:43 +0000354 */
Paul Bakker40e46942009-01-03 21:51:57 +0000355#define POLARSSL_ARC4_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000356
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000357/**
Paul Bakkerefc30292011-11-10 14:43:23 +0000358 * \def POLARSSL_ASN1_PARSE_C
359 *
360 * Enable the generic ASN1 parser.
361 *
362 * Module: library/asn1.c
363 * Caller: library/x509parse.c
364 */
365#define POLARSSL_ASN1_PARSE_C
366
367/**
Paul Bakkerbdb912d2012-02-13 23:11:30 +0000368 * \def POLARSSL_ASN1_WRITE_C
369 *
370 * Enable the generic ASN1 writer.
371 *
372 * Module: library/asn1write.c
373 */
374#define POLARSSL_ASN1_WRITE_C
375
376/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000377 * \def POLARSSL_BASE64_C
378 *
379 * Enable the Base64 module.
380 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000381 * Module: library/base64.c
Paul Bakker5690efc2011-05-26 13:16:06 +0000382 * Caller: library/pem.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000383 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000384 * This module is required for PEM support (required by X.509).
Paul Bakker5121ce52009-01-03 21:22:43 +0000385 */
Paul Bakker40e46942009-01-03 21:51:57 +0000386#define POLARSSL_BASE64_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000387
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000388/**
389 * \def POLARSSL_BIGNUM_C
390 *
Paul Bakker9a736322012-11-14 12:39:52 +0000391 * Enable the multi-precision integer library.
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000392 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000393 * Module: library/bignum.c
394 * Caller: library/dhm.c
395 * library/rsa.c
396 * library/ssl_tls.c
397 * library/x509parse.c
398 *
399 * This module is required for RSA and DHM support.
400 */
Paul Bakker40e46942009-01-03 21:51:57 +0000401#define POLARSSL_BIGNUM_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000402
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000403/**
Paul Bakkera9379c02012-07-04 11:02:11 +0000404 * \def POLARSSL_BLOWFISH_C
405 *
406 * Enable the Blowfish block cipher.
407 *
408 * Module: library/blowfish.c
409 */
410#define POLARSSL_BLOWFISH_C
411
412/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000413 * \def POLARSSL_CAMELLIA_C
414 *
415 * Enable the Camellia block cipher.
416 *
Paul Bakker38119b12009-01-10 23:31:23 +0000417 * Module: library/camellia.c
Paul Bakker13e2dfe2009-07-28 07:18:38 +0000418 * Caller: library/ssl_tls.c
Paul Bakker38119b12009-01-10 23:31:23 +0000419 *
Paul Bakker645ce3a2012-10-31 12:32:41 +0000420 * This module enables the following ciphersuites (if other requisites are
421 * enabled as well):
422 * TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
423 * TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
424 * TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
425 * TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
426 * TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
427 * TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
428 * TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
429 * TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
Paul Bakker38119b12009-01-10 23:31:23 +0000430 */
431#define POLARSSL_CAMELLIA_C
432
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000433/**
434 * \def POLARSSL_CERTS_C
435 *
436 * Enable the test certificates.
437 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000438 * Module: library/certs.c
439 * Caller:
440 *
441 * This module is used for testing (ssl_client/server).
442 */
Paul Bakker40e46942009-01-03 21:51:57 +0000443#define POLARSSL_CERTS_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000444
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000445/**
446 * \def POLARSSL_CIPHER_C
447 *
448 * Enable the generic cipher layer.
449 *
Paul Bakker8123e9d2011-01-06 15:37:30 +0000450 * Module: library/cipher.c
451 * Caller:
452 *
453 * Uncomment to enable generic cipher wrappers.
454 */
455#define POLARSSL_CIPHER_C
456
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000457/**
Paul Bakker0e04d0e2011-11-27 14:46:59 +0000458 * \def POLARSSL_CTR_DRBG_C
459 *
460 * Enable the CTR_DRBG AES-256-based random generator
461 *
462 * Module: library/ctr_drbg.c
463 * Caller:
464 *
Paul Bakker6083fd22011-12-03 21:45:14 +0000465 * Requires: POLARSSL_AES_C
466 *
Paul Bakker0e04d0e2011-11-27 14:46:59 +0000467 * This module provides the CTR_DRBG AES-256 random number generator.
468 */
469#define POLARSSL_CTR_DRBG_C
470
471/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000472 * \def POLARSSL_DEBUG_C
473 *
474 * Enable the debug functions.
475 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000476 * Module: library/debug.c
477 * Caller: library/ssl_cli.c
478 * library/ssl_srv.c
479 * library/ssl_tls.c
480 *
481 * This module provides debugging functions.
482 */
Paul Bakker40e46942009-01-03 21:51:57 +0000483#define POLARSSL_DEBUG_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000484
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000485/**
486 * \def POLARSSL_DES_C
487 *
488 * Enable the DES block cipher.
489 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000490 * Module: library/des.c
Paul Bakker6deb37e2013-02-19 13:17:08 +0100491 * Caller: library/pem.c
492 * library/ssl_tls.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000493 *
Paul Bakker645ce3a2012-10-31 12:32:41 +0000494 * This module enables the following ciphersuites (if other requisites are
495 * enabled as well):
496 * TLS_RSA_WITH_3DES_EDE_CBC_SHA
497 * TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
Paul Bakker6deb37e2013-02-19 13:17:08 +0100498 *
499 * PEM uses DES/3DES for decrypting encrypted keys.
Paul Bakker5121ce52009-01-03 21:22:43 +0000500 */
Paul Bakker40e46942009-01-03 21:51:57 +0000501#define POLARSSL_DES_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000502
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000503/**
504 * \def POLARSSL_DHM_C
505 *
506 * Enable the Diffie-Hellman-Merkle key exchange.
507 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000508 * Module: library/dhm.c
509 * Caller: library/ssl_cli.c
510 * library/ssl_srv.c
511 *
Paul Bakker645ce3a2012-10-31 12:32:41 +0000512 * This module enables the following ciphersuites (if other requisites are
513 * enabled as well):
514 * TLS_DHE_RSA_WITH_DES_CBC_SHA
515 * TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
516 * TLS_DHE_RSA_WITH_AES_128_CBC_SHA
517 * TLS_DHE_RSA_WITH_AES_256_CBC_SHA
518 * TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
519 * TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
520 * TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
521 * TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
522 * TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
523 * TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
524 * TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
525 * TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
Paul Bakker5121ce52009-01-03 21:22:43 +0000526 */
Paul Bakker40e46942009-01-03 21:51:57 +0000527#define POLARSSL_DHM_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000528
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000529/**
Paul Bakker6083fd22011-12-03 21:45:14 +0000530 * \def POLARSSL_ENTROPY_C
531 *
532 * Enable the platform-specific entropy code.
533 *
534 * Module: library/entropy.c
535 * Caller:
536 *
537 * Requires: POLARSSL_SHA4_C
538 *
539 * This module provides a generic entropy pool
540 */
541#define POLARSSL_ENTROPY_C
542
543/**
Paul Bakker9d781402011-05-09 16:17:09 +0000544 * \def POLARSSL_ERROR_C
545 *
546 * Enable error code to error string conversion.
547 *
548 * Module: library/error.c
549 * Caller:
550 *
551 * This module enables err_strerror().
552 */
553#define POLARSSL_ERROR_C
554
555/**
Paul Bakker89e80c92012-03-20 13:50:09 +0000556 * \def POLARSSL_GCM_C
557 *
558 * Enable the Galois/Counter Mode (GCM) for AES
559 *
560 * Module: library/gcm.c
561 *
562 * Requires: POLARSSL_AES_C
Paul Bakker645ce3a2012-10-31 12:32:41 +0000563 *
564 * This module enables the following ciphersuites (if other requisites are
565 * enabled as well):
566 * TLS_RSA_WITH_AES_128_GCM_SHA256
567 * TLS_RSA_WITH_AES_256_GCM_SHA384
Paul Bakker89e80c92012-03-20 13:50:09 +0000568 */
569#define POLARSSL_GCM_C
570
571/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000572 * \def POLARSSL_HAVEGE_C
573 *
574 * Enable the HAVEGE random generator.
575 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000576 * Module: library/havege.c
577 * Caller:
578 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000579 * Requires: POLARSSL_TIMING_C
580 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000581 * This module enables the HAVEGE random number generator.
582 */
Paul Bakker40e46942009-01-03 21:51:57 +0000583#define POLARSSL_HAVEGE_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000584
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000585/**
586 * \def POLARSSL_MD_C
587 *
588 * Enable the generic message digest layer.
589 *
Paul Bakker17373852011-01-06 14:20:01 +0000590 * Module: library/md.c
591 * Caller:
592 *
593 * Uncomment to enable generic message digest wrappers.
594 */
595#define POLARSSL_MD_C
596
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000597/**
598 * \def POLARSSL_MD2_C
599 *
600 * Enable the MD2 hash algorithm
601 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000602 * Module: library/md2.c
603 * Caller: library/x509parse.c
604 *
605 * Uncomment to enable support for (rare) MD2-signed X.509 certs.
606 *
Paul Bakker13e2dfe2009-07-28 07:18:38 +0000607#define POLARSSL_MD2_C
Paul Bakker6506aff2009-07-28 20:52:02 +0000608 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000609
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000610/**
611 * \def POLARSSL_MD4_C
612 *
613 * Enable the MD4 hash algorithm
614 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000615 * Module: library/md4.c
616 * Caller: library/x509parse.c
617 *
618 * Uncomment to enable support for (rare) MD4-signed X.509 certs.
619 *
Paul Bakker13e2dfe2009-07-28 07:18:38 +0000620#define POLARSSL_MD4_C
Paul Bakker6506aff2009-07-28 20:52:02 +0000621 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000622
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000623/**
624 * \def POLARSSL_MD5_C
625 *
626 * Enable the MD5 hash algorithm
627 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000628 * Module: library/md5.c
Paul Bakker6deb37e2013-02-19 13:17:08 +0100629 * Caller: library/pem.c
630 * library/ssl_tls.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000631 * library/x509parse.c
632 *
633 * This module is required for SSL/TLS and X.509.
Paul Bakker6deb37e2013-02-19 13:17:08 +0100634 * PEM uses MD5 for decrypting encrypted keys.
Paul Bakker5121ce52009-01-03 21:22:43 +0000635 */
Paul Bakker40e46942009-01-03 21:51:57 +0000636#define POLARSSL_MD5_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000637
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000638/**
639 * \def POLARSSL_NET_C
640 *
641 * Enable the TCP/IP networking routines.
642 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000643 * Module: library/net.c
644 * Caller:
645 *
646 * This module provides TCP/IP networking routines.
647 */
Paul Bakker40e46942009-01-03 21:51:57 +0000648#define POLARSSL_NET_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000649
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000650/**
651 * \def POLARSSL_PADLOCK_C
652 *
653 * Enable VIA Padlock support on x86.
654 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000655 * Module: library/padlock.c
656 * Caller: library/aes.c
657 *
658 * This modules adds support for the VIA PadLock on x86.
659 */
Paul Bakker40e46942009-01-03 21:51:57 +0000660#define POLARSSL_PADLOCK_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000661
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000662/**
Paul Bakkerf518b162012-08-23 13:03:18 +0000663 * \def POLARSSL_PBKDF2_C
664 *
665 * Enable PKCS#5 PBKDF2 key derivation function
666 *
667 * Module: library/pbkdf2.c
668 *
669 * Requires: POLARSSL_MD_C
670 *
671 * This module adds support for the PKCS#5 PBKDF2 key derivation function.
672#define POLARSSL_PBKDF2_C
673 */
674
675/**
Paul Bakker96743fc2011-02-12 14:30:57 +0000676 * \def POLARSSL_PEM_C
677 *
678 * Enable PEM decoding
679 *
680 * Module: library/pem.c
681 * Caller: library/x509parse.c
682 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000683 * Requires: POLARSSL_BASE64_C
684 *
Paul Bakker96743fc2011-02-12 14:30:57 +0000685 * This modules adds support for decoding PEM files.
686 */
687#define POLARSSL_PEM_C
688
689/**
Paul Bakker5690efc2011-05-26 13:16:06 +0000690 * \def POLARSSL_PKCS11_C
691 *
Paul Bakkereb2c6582012-09-27 19:15:01 +0000692 * Enable wrapper for PKCS#11 smartcard support.
Paul Bakker5690efc2011-05-26 13:16:06 +0000693 *
694 * Module: library/ssl_srv.c
695 * Caller: library/ssl_cli.c
696 * library/ssl_srv.c
697 *
698 * Requires: POLARSSL_SSL_TLS_C
699 *
Paul Bakkereb2c6582012-09-27 19:15:01 +0000700 * This module enables SSL/TLS PKCS #11 smartcard support.
Paul Bakker5690efc2011-05-26 13:16:06 +0000701 * Requires the presence of the PKCS#11 helper library (libpkcs11-helper)
702#define POLARSSL_PKCS11_C
703 */
704
705/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000706 * \def POLARSSL_RSA_C
707 *
708 * Enable the RSA public-key cryptosystem.
709 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000710 * Module: library/rsa.c
711 * Caller: library/ssl_cli.c
712 * library/ssl_srv.c
713 * library/ssl_tls.c
714 * library/x509.c
715 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000716 * Requires: POLARSSL_BIGNUM_C
717 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000718 * This module is required for SSL/TLS and MD5-signed certificates.
719 */
Paul Bakker40e46942009-01-03 21:51:57 +0000720#define POLARSSL_RSA_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000721
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000722/**
723 * \def POLARSSL_SHA1_C
724 *
725 * Enable the SHA1 cryptographic hash algorithm.
726 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000727 * Module: library/sha1.c
728 * Caller: library/ssl_cli.c
729 * library/ssl_srv.c
730 * library/ssl_tls.c
731 * library/x509parse.c
732 *
733 * This module is required for SSL/TLS and SHA1-signed certificates.
734 */
Paul Bakker40e46942009-01-03 21:51:57 +0000735#define POLARSSL_SHA1_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000736
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000737/**
738 * \def POLARSSL_SHA2_C
739 *
740 * Enable the SHA-224 and SHA-256 cryptographic hash algorithms.
741 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000742 * Module: library/sha2.c
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000743 * Caller: library/md_wrap.c
744 * library/x509parse.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000745 *
746 * This module adds support for SHA-224 and SHA-256.
Paul Bakker769075d2012-11-24 11:26:46 +0100747 * This module is required for the SSL/TLS 1.2 PRF function.
Paul Bakker5121ce52009-01-03 21:22:43 +0000748 */
Paul Bakker40e46942009-01-03 21:51:57 +0000749#define POLARSSL_SHA2_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000750
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000751/**
752 * \def POLARSSL_SHA4_C
753 *
754 * Enable the SHA-384 and SHA-512 cryptographic hash algorithms.
755 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000756 * Module: library/sha4.c
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000757 * Caller: library/md_wrap.c
758 * library/x509parse.c
Paul Bakker5121ce52009-01-03 21:22:43 +0000759 *
760 * This module adds support for SHA-384 and SHA-512.
761 */
Paul Bakker40e46942009-01-03 21:51:57 +0000762#define POLARSSL_SHA4_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000763
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000764/**
Paul Bakker0a597072012-09-25 21:55:46 +0000765 * \def POLARSSL_SSL_CACHE_C
766 *
767 * Enable simple SSL cache implementation.
768 *
769 * Module: library/ssl_cache.c
770 * Caller:
771 *
772 * Requires: POLARSSL_SSL_CACHE_C
773 */
774#define POLARSSL_SSL_CACHE_C
775
776/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000777 * \def POLARSSL_SSL_CLI_C
778 *
779 * Enable the SSL/TLS client code.
780 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000781 * Module: library/ssl_cli.c
782 * Caller:
783 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000784 * Requires: POLARSSL_SSL_TLS_C
785 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000786 * This module is required for SSL/TLS client support.
787 */
Paul Bakker40e46942009-01-03 21:51:57 +0000788#define POLARSSL_SSL_CLI_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000789
Paul Bakker9a736322012-11-14 12:39:52 +0000790/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000791 * \def POLARSSL_SSL_SRV_C
792 *
793 * Enable the SSL/TLS server code.
794 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000795 * Module: library/ssl_srv.c
796 * Caller:
797 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000798 * Requires: POLARSSL_SSL_TLS_C
799 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000800 * This module is required for SSL/TLS server support.
801 */
Paul Bakker40e46942009-01-03 21:51:57 +0000802#define POLARSSL_SSL_SRV_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000803
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000804/**
805 * \def POLARSSL_SSL_TLS_C
806 *
Paul Bakkere29ab062011-05-18 13:26:54 +0000807 * Enable the generic SSL/TLS code.
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000808 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000809 * Module: library/ssl_tls.c
810 * Caller: library/ssl_cli.c
811 * library/ssl_srv.c
812 *
Paul Bakker5690efc2011-05-26 13:16:06 +0000813 * Requires: POLARSSL_MD5_C, POLARSSL_SHA1_C, POLARSSL_X509_PARSE_C
814 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000815 * This module is required for SSL/TLS.
816 */
Paul Bakker40e46942009-01-03 21:51:57 +0000817#define POLARSSL_SSL_TLS_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000818
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000819/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000820 * \def POLARSSL_TIMING_C
821 *
822 * Enable the portable timing interface.
823 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000824 * Module: library/timing.c
825 * Caller: library/havege.c
826 *
827 * This module is used by the HAVEGE random number generator.
828 */
Paul Bakker40e46942009-01-03 21:51:57 +0000829#define POLARSSL_TIMING_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000830
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000831/**
832 * \def POLARSSL_VERSION_C
833 *
834 * Enable run-time version information.
835 *
Paul Bakker0a62cd12011-01-21 11:00:08 +0000836 * Module: library/version.c
837 *
838 * This module provides run-time version information.
839 */
840#define POLARSSL_VERSION_C
841
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000842/**
843 * \def POLARSSL_X509_PARSE_C
844 *
845 * Enable X.509 certificate parsing.
846 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000847 * Module: library/x509parse.c
848 * Caller: library/ssl_cli.c
849 * library/ssl_srv.c
850 * library/ssl_tls.c
851 *
Paul Bakkerefc30292011-11-10 14:43:23 +0000852 * Requires: POLARSSL_ASN1_PARSE_C, POLARSSL_BIGNUM_C, POLARSSL_RSA_C
Paul Bakker5690efc2011-05-26 13:16:06 +0000853 *
Paul Bakker5121ce52009-01-03 21:22:43 +0000854 * This module is required for X.509 certificate parsing.
855 */
Paul Bakker40e46942009-01-03 21:51:57 +0000856#define POLARSSL_X509_PARSE_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000857
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000858/**
Paul Bakkerbdb912d2012-02-13 23:11:30 +0000859 * \def POLARSSL_X509_WRITE_C
860 *
861 * Enable X.509 buffer writing.
862 *
863 * Module: library/x509write.c
864 *
865 * Requires: POLARSSL_BIGNUM_C, POLARSSL_RSA_C
866 *
867 * This module is required for X.509 certificate request writing.
868 */
869#define POLARSSL_X509_WRITE_C
870
871/**
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000872 * \def POLARSSL_XTEA_C
Paul Bakker5121ce52009-01-03 21:22:43 +0000873 *
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000874 * Enable the XTEA block cipher.
875 *
Paul Bakker7a7c78f2009-01-04 18:15:48 +0000876 * Module: library/xtea.c
877 * Caller:
878 */
879#define POLARSSL_XTEA_C
Paul Bakker0a62cd12011-01-21 11:00:08 +0000880/* \} name */
Paul Bakker7a7c78f2009-01-04 18:15:48 +0000881
Paul Bakker5121ce52009-01-03 21:22:43 +0000882#endif /* config.h */