Re: how do I test if NSS supports an algorithm at build time?

Andrew Cagney <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAJeAr6vpsO3MiKUrd=HSuHsDaSBt5ny5xOHOvctQVK2B6DmSWA@mail.gmail.com>
On 7 February 2018 at 11:45, Andrew Cagney <[email protected]> wrote:
> On 7 February 2018 at 10:41, Franziskus Kiefer <[email protected]> wrote:
>> You should probably try to detect this at runtime.
>> At compile time you can simply check if SEC_OID_CURVE25519 exists and fail
>> (or do something else) if it doesn't.

If SEC_OID_CURVE25519 was a #define then a build time test would be
easy.  Alas, it's an enum.
So without sucking in autoconf, is there some official proxy for this.
If all else fails there should be a version number in the header.

>> At runtime you could try using SEC_OID_CURVE25519 (with your own define to
>> 355) and have a fallback if NSS gives you an error on using it.

While NSS has what I'll loosely describe as its ABI guarantee and this
magic should work.  I'd rather to not go there.

I'm more comfortable with building against version X and only accept
version >=X at runtime.

Andrew
-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.