Fix some unguarded references to EC code inside the FIPS provider.
Reviewed-by: Paul Yang <kaishen.yy@antfin.com>
Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/9543)
BIGNUM *a = NULL, *b = NULL;
unsigned char randbuf[128];
RAND_DRBG *drbg = OPENSSL_CTX_get0_public_drbg(libctx);
+#ifndef OPENSSL_NO_EC
EC_KEY *key = NULL;
+#endif
if (ctx == NULL || sha256 == NULL || drbg == NULL)
goto err;
if (!BN_rand_ex(a, 256, BN_RAND_TOP_ANY, BN_RAND_BOTTOM_ANY, bnctx))
goto err;
+#ifndef OPENSSL_NO_EC
/* Do some dummy EC calls */
key = EC_KEY_new_by_curve_name_ex(libctx, NID_X9_62_prime256v1);
if (key == NULL)
if (!EC_KEY_generate_key(key))
goto err;
+#endif
ret = 1;
err:
EVP_MD_CTX_free(ctx);
EVP_MD_meth_free(sha256);
+#ifndef OPENSSL_NO_EC
EC_KEY_free(key);
+#endif
return ret;
}