@@ -5265,7 +5265,8 @@ AS_CASE([$FIPS_VERSION],
52655265
52665266 AS_IF ( [ test "x$ENABLED_ECCCUSTCURVES" != "xno" &&
52675267 test "$FIPS_VERSION" != "dev"] ,
5268- [ ENABLED_ECCCUSTCURVES="no"] )
5268+ [ AC_MSG_WARN ( [ Forcing off ecccustcurves for FIPS ${FIPS_VERSION}.] )
5269+ ENABLED_ECCCUSTCURVES="no"] )
52695270
52705271# Hashing section
52715272 AS_IF ( [ test "x$ENABLED_SHA3" != "xyes" &&
@@ -5348,7 +5349,8 @@ AS_CASE([$FIPS_VERSION],
53485349
53495350# Old TLS requires MD5 + HMAC, which is not allowed under FIPS 140-3
53505351 AS_IF ( [ test "$ENABLED_OLD_TLS" != "no"] ,
5351- [ ENABLED_OLD_TLS="no"; AM_CFLAGS="$AM_CFLAGS -DNO_OLD_TLS"] )
5352+ [ AC_MSG_WARN ( [ Forcing off oldtls for FIPS ${FIPS_VERSION}.] )
5353+ ENABLED_OLD_TLS="no"; AM_CFLAGS="$AM_CFLAGS -DNO_OLD_TLS"] )
53525354
53535355 ],
53545356 [ v5*] , [ # FIPS 140-3
@@ -5392,7 +5394,8 @@ AS_CASE([$FIPS_VERSION],
53925394
53935395 AS_IF ( [ test "$ENABLED_COMPKEY" = "yes" &&
53945396 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_compkey" != "yes")] ,
5395- [ ENABLED_COMPKEY="no"] )
5397+ [ AC_MSG_WARN ( [ Forcing off compkey for FIPS ${FIPS_VERSION}.] )
5398+ ENABLED_COMPKEY="no"] )
53965399
53975400 AS_IF ( [ test "$ENABLED_SHA224" != "yes" &&
53985401 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_sha224" != "no")] ,
@@ -5409,12 +5412,14 @@ AS_CASE([$FIPS_VERSION],
54095412 # Shake128 is a SHA-3 algorithm outside the v5 FIPS algorithm list
54105413 AS_IF ( [ test "$ENABLED_SHAKE128" != "no" &&
54115414 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_shake128" != "yes")] ,
5412- [ ENABLED_SHAKE128=no; AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NO_SHAKE128"] )
5415+ [ AC_MSG_WARN ( [ Forcing off shake128 for FIPS ${FIPS_VERSION}.] )
5416+ ENABLED_SHAKE128=no; AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NO_SHAKE128"] )
54135417
54145418 # Shake256 is a SHA-3 algorithm outside the v5 FIPS algorithm list
54155419 AS_IF ( [ test "$ENABLED_SHAKE256" != "no" &&
54165420 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_shake256" != "yes")] ,
5417- [ ENABLED_SHAKE256=no; AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NO_SHAKE256"] )
5421+ [ AC_MSG_WARN ( [ Forcing off shake256 for FIPS ${FIPS_VERSION}.] )
5422+ ENABLED_SHAKE256=no; AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NO_SHAKE256"] )
54185423
54195424 # SHA512-224 and SHA512-256 are SHA-2 algorithms outside the v5 FIPS algorithm list
54205425 AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NOSHA512_224 -DWOLFSSL_NOSHA512_256"
@@ -5425,7 +5430,8 @@ AS_CASE([$FIPS_VERSION],
54255430
54265431 AS_IF ( [ test "$ENABLED_AESXTS" = "yes" &&
54275432 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_aesxts" != "yes")] ,
5428- [ ENABLED_AESXTS="no"] )
5433+ [ AC_MSG_WARN ( [ Forcing off aesxts for FIPS ${FIPS_VERSION}.] )
5434+ ENABLED_AESXTS="no"] )
54295435
54305436 AS_IF ( [ test "$ENABLED_RSAPSS" != "yes" &&
54315437 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_rsapss" != "no")] ,
@@ -5464,11 +5470,13 @@ AS_CASE([$FIPS_VERSION],
54645470 # AES-GCM streaming isn't part of the v5 FIPS suite.
54655471 AS_IF ( [ test "$ENABLED_AESGCM_STREAM" = "yes" &&
54665472 (test "$FIPS_VERSION" != "v5-dev" || test "$enable_aesgcm_stream" != "yes")] ,
5467- [ ENABLED_AESGCM_STREAM="no"] )
5473+ [ AC_MSG_WARN ( [ Forcing off aesgcm-stream for FIPS ${FIPS_VERSION}.] )
5474+ ENABLED_AESGCM_STREAM="no"] )
54685475
54695476 # Old TLS requires MD5 + HMAC, which is not allowed under FIPS 140-3
54705477 AS_IF ( [ test "$ENABLED_OLD_TLS" != "no"] ,
5471- [ ENABLED_OLD_TLS="no"; AM_CFLAGS="$AM_CFLAGS -DNO_OLD_TLS"] )
5478+ [ AC_MSG_WARN ( [ Forcing off oldtls for FIPS ${FIPS_VERSION}.] )
5479+ ENABLED_OLD_TLS="no"; AM_CFLAGS="$AM_CFLAGS -DNO_OLD_TLS"] )
54725480
54735481 AS_IF ( [ test $HAVE_FIPS_VERSION_MINOR -ge 2] ,
54745482 [ AS_IF ( [ test "x$ENABLED_AESOFB" = "xno" &&
0 commit comments