1 | dnl Process this file with autoconf to produce a configure script. |
1 | dnl Process this file with autoconf to produce a configure script. |
2 | |
2 | |
3 | AC_PREREQ(2.59) |
3 | AC_PREREQ(2.69) |
4 | AC_INIT |
4 | AC_INIT |
5 | AC_CONFIG_SRCDIR([src/gvpe.C]) |
5 | AC_CONFIG_SRCDIR([src/gvpe.C]) |
6 | AC_CANONICAL_TARGET |
6 | AC_CANONICAL_TARGET |
7 | AM_INIT_AUTOMAKE(gvpe, 1.9) |
7 | AM_INIT_AUTOMAKE(gvpe, 3.1) |
8 | AC_CONFIG_HEADERS([config.h]) |
8 | AC_CONFIG_HEADERS([config.h]) |
9 | AM_MAINTAINER_MODE |
9 | AM_MAINTAINER_MODE |
10 | |
10 | |
11 | AH_TOP([ |
11 | AH_TOP([ |
12 | #ifndef CONFIG_H__ |
12 | #ifndef CONFIG_H__ |
… | |
… | |
46 | #else |
46 | #else |
47 | # define CLOCALE <locale.h> |
47 | # define CLOCALE <locale.h> |
48 | #endif |
48 | #endif |
49 | ]) |
49 | ]) |
50 | |
50 | |
51 | dnl Include the macros from the m4/ directory |
|
|
52 | AM_ACLOCAL_INCLUDE(m4) |
|
|
53 | |
|
|
54 | AM_GNU_GETTEXT([external]) |
51 | AM_GNU_GETTEXT([external]) |
55 | AM_GNU_GETTEXT_VERSION(0.11.5) |
52 | AM_GNU_GETTEXT_VERSION(0.11.5) |
56 | |
53 | |
57 | # Enable GNU extensions. |
54 | # Enable GNU extensions. |
58 | # Define this here, not in acconfig's @TOP@ section, since definitions |
55 | # Define this here, not in acconfig's @TOP@ section, since definitions |
59 | # in the latter don't make it into the configure-time tests. |
56 | # in the latter don't make it into the configure-time tests. |
60 | AC_DEFINE([_GNU_SOURCE], 1, [Enable GNU extenstions]) |
57 | AC_DEFINE([_GNU_SOURCE], 1, [Enable GNU extensions]) |
61 | |
58 | |
62 | # do NOT define POSIX_SOURCE, sicne this clashes with many BSDs |
59 | # do NOT define POSIX_SOURCE, sicne this clashes with many BSDs |
63 | dnl AC_DEFINE([_POSIX_SOURCE], 1, [Enable POSIX 1003.1 extensions]) |
60 | dnl AC_DEFINE([_POSIX_SOURCE], 1, [Enable POSIX 1003.1 extensions]) |
64 | dnl AC_DEFINE([_XOPEN_SOURCE], 500, [Enable XOPEN extensions]) |
61 | dnl AC_DEFINE([_XOPEN_SOURCE], 500, [Enable XOPEN extensions]) |
65 | |
62 | |
66 | ALL_LINGUAS="" |
63 | ALL_LINGUAS="" |
67 | |
64 | |
68 | dnl Checks for programs. |
65 | dnl Checks for programs. |
69 | AC_PROG_CC |
|
|
70 | AC_PROG_CPP |
66 | AC_PROG_CPP |
71 | AC_PROG_CXX |
67 | AC_PROG_CXX |
72 | AC_PROG_GCC_TRADITIONAL |
68 | AC_PROG_GCC_TRADITIONAL |
73 | AC_PROG_AWK |
69 | AC_PROG_AWK |
74 | AC_PROG_INSTALL |
70 | AC_PROG_INSTALL |
… | |
… | |
77 | AC_PROG_RANLIB |
73 | AC_PROG_RANLIB |
78 | |
74 | |
79 | AC_ARG_ENABLE(iftype, |
75 | AC_ARG_ENABLE(iftype, |
80 | [AS_HELP_STRING(--enable-iftype=TYPE/SUBTYPE, |
76 | [AS_HELP_STRING(--enable-iftype=TYPE/SUBTYPE, |
81 | Use kernel/net device interface TYPE/SUBTYPE. |
77 | Use kernel/net device interface TYPE/SUBTYPE. |
82 | Working combinations are: |
78 | Working combinations are (see doc/gvpe.osdep.5.pod): |
83 | "native/linux" |
79 | "native/linux" |
84 | "tincd/linux" |
80 | "tincd/linux" |
|
|
81 | "tincd/netbsd" |
85 | "tincd/freebsd" |
82 | "tincd/freebsd" |
86 | "tincd/openbsd" |
83 | "tincd/openbsd" |
|
|
84 | "native/darwin" |
87 | "tincd/darwin" |
85 | "tincd/darwin" |
88 | "native/cygwin"; |
86 | "native/cygwin"; |
89 | Untested combinations are: |
87 | Untested combinations are: |
90 | "native/darwin" |
|
|
91 | "tincd/netbsd" |
88 | "tincd/bsd" |
92 | "tincd/solaris" |
89 | "tincd/solaris" |
93 | "tincd/mingw" |
90 | "tincd/mingw" |
94 | "tincd/raw_socket" |
91 | "tincd/raw_socket" |
95 | "tincd/uml_socket"; |
92 | "tincd/uml_socket"; |
96 | Broken combinations are: |
93 | Broken combinations are: |
… | |
… | |
157 | AC_CACHE_SAVE |
154 | AC_CACHE_SAVE |
158 | |
155 | |
159 | dnl Checks for libraries. |
156 | dnl Checks for libraries. |
160 | |
157 | |
161 | AC_LANG(C++) |
158 | AC_LANG(C++) |
162 | AC_CHECK_HEADERS(ext/hash_map clocale) |
159 | AC_CHECK_HEADERS(tr1/unordered_map ext/hash_map clocale) |
163 | |
160 | |
164 | dnl Checks for header files. |
161 | dnl Checks for header files. |
165 | AC_CHECK_HEADERS([fcntl.h inttypes.h limits.h malloc.h stdint.h strings.h syslog.h unistd.h \ |
162 | AC_CHECK_HEADERS([fcntl.h inttypes.h limits.h malloc.h stdint.h strings.h syslog.h unistd.h \ |
166 | sys/file.h sys/ioctl.h sys/param.h sys/time.h netinet/in_systm.h sys/cygwin.h \ |
163 | sys/file.h sys/ioctl.h sys/param.h sys/time.h netinet/in_systm.h sys/cygwin.h \ |
167 | sys/mman.h netinet/in.h]) |
164 | sys/mman.h netinet/in.h]) |
… | |
… | |
225 | ]) |
222 | ]) |
226 | AC_CHECK_FUNC(gethostbyname, [], [ |
223 | AC_CHECK_FUNC(gethostbyname, [], [ |
227 | AC_CHECK_LIB(nsl, gethostbyname) |
224 | AC_CHECK_LIB(nsl, gethostbyname) |
228 | ]) |
225 | ]) |
229 | |
226 | |
|
|
227 | dnl libev support |
|
|
228 | m4_include([libev/libev.m4]) |
|
|
229 | |
230 | AC_LANG_POP |
230 | AC_LANG_POP |
231 | |
231 | |
232 | dnl AC_CHECK_FUNCS([freeaddrinfo gai_strerror getaddrinfo getnameinfo]) |
232 | dnl AC_CHECK_FUNCS([freeaddrinfo gai_strerror getaddrinfo getnameinfo]) |
233 | |
233 | |
234 | AC_CACHE_SAVE |
234 | AC_CACHE_SAVE |
235 | |
235 | |
236 | dnl These are defined in files in m4/ |
236 | dnl These are defined in files in m4/ |
237 | tinc_TUNTAP |
237 | tinc_TUNTAP |
238 | |
238 | |
239 | tinc_OPENSSL |
239 | PKG_CHECK_MODULES([LIBCRYPTO], [libcrypto >= 1]) |
240 | if test "x$openssl_include" != x; then |
240 | |
241 | CXXFLAGS="$CXXFLAGS -I$openssl_include" |
241 | AC_ARG_ENABLE(threads, |
|
|
242 | [AS_HELP_STRING(--enable-threads,try to use threads for long-running asynchronous operations (default enabled).)], |
|
|
243 | [try_threads=$enableval], |
|
|
244 | [try_threads=yes] |
|
|
245 | ) |
|
|
246 | |
|
|
247 | if test "x$try_threads" = xyes; then |
|
|
248 | AC_CHECK_HEADER(pthread.h,[ |
|
|
249 | LIBS="$LIBS -lpthread" |
|
|
250 | AC_COMPILE_IFELSE( |
|
|
251 | [AC_LANG_PROGRAM([#include <pthread.h>], [pthread_t id; pthread_create (&id, 0, 0, 0);])], |
|
|
252 | [AC_DEFINE_UNQUOTED(ENABLE_PTHREADS, 1, [POSIX thread support.])] |
|
|
253 | ) |
|
|
254 | ]) |
242 | fi |
255 | fi |
243 | dnl tinc_ZLIB |
|
|
244 | |
256 | |
245 | AC_ARG_ENABLE(static-daemon, |
257 | AC_ARG_ENABLE(static-daemon, |
246 | [AS_HELP_STRING(--enable-static-daemon,enable statically linked daemon.)], |
258 | [AS_HELP_STRING(--enable-static-daemon,enable statically linked daemon.)], |
247 | [LDFLAGS_DAEMON=-static] |
259 | [LDFLAGS_DAEMON=-static] |
248 | ) |
260 | ) |
249 | AC_SUBST(LDFLAGS_DAEMON) |
261 | AC_SUBST(LDFLAGS_DAEMON) |
250 | |
262 | |
251 | AC_ARG_ENABLE(rohc, |
263 | dnl AC_ARG_ENABLE(rohc, |
252 | [AS_HELP_STRING(--enable-rohc,enable robust header compression (rfc3095).)], |
264 | dnl [AS_HELP_STRING(--enable-rohc,enable robust header compression (rfc3095).)], |
253 | [ |
265 | dnl [ |
254 | echo |
266 | dnl echo |
255 | echo "**********************************************************************" |
267 | dnl echo "**********************************************************************" |
256 | echo "**********************************************************************" |
268 | dnl echo "**********************************************************************" |
257 | echo "**** --enable-rohc is highly experimental, do not use ****************" |
269 | dnl echo "**** --enable-rohc is highly experimental, do not use ****************" |
258 | echo "**********************************************************************" |
270 | dnl echo "**********************************************************************" |
259 | echo "**********************************************************************" |
271 | dnl echo "**********************************************************************" |
260 | echo |
272 | dnl echo |
261 | rohc=true |
273 | dnl rohc=true |
262 | AC_DEFINE_UNQUOTED(ENABLE_ROHC, 1, [ROHC support]) |
274 | dnl AC_DEFINE_UNQUOTED(ENABLE_ROHC, 1, [ROHC support]) |
263 | ] |
275 | dnl ] |
264 | ) |
276 | dnl ) |
265 | |
277 | |
266 | AM_CONDITIONAL(ROHC, test x$rohc = xtrue) |
278 | AM_CONDITIONAL(ROHC, test x$rohc = xtrue) |
267 | |
279 | |
|
|
280 | dnl AC_ARG_ENABLE(bridging, |
|
|
281 | dnl [AS_HELP_STRING(--enable-bridging,enable bridging support (default disabled).)], |
|
|
282 | dnl AC_DEFINE_UNQUOTED(ENABLE_BRIDGING, 1, [bridging support.]) |
|
|
283 | dnl ) |
|
|
284 | |
|
|
285 | ICMP=1 |
268 | AC_ARG_ENABLE(icmp, |
286 | AC_ARG_ENABLE(icmp, |
269 | [AS_HELP_STRING(--enable-icmp,enable icmp protocol support (default disabled).)], |
287 | [AS_HELP_STRING(--disable-icmp,enable icmp protocol support (default enabled).)], |
|
|
288 | if test "x$enableval" = xno; then |
|
|
289 | ICMP=0 |
|
|
290 | fi |
|
|
291 | ) |
|
|
292 | if test "x$ICMP" = x1; then |
270 | AC_DEFINE_UNQUOTED(ENABLE_ICMP, 1, [ICMP protocol support.]) |
293 | AC_DEFINE_UNQUOTED(ENABLE_ICMP, 1, [ICMP protocol support.]) |
271 | ) |
294 | fi |
272 | |
295 | |
|
|
296 | TCP=1 |
273 | AC_ARG_ENABLE(tcp, |
297 | AC_ARG_ENABLE(tcp, |
274 | [AS_HELP_STRING(--enable-tcp,enable tcp protocol support (default disabled).)], |
298 | [AS_HELP_STRING(--disable-tcp,enable tcp protocol support (default enabled).)], |
|
|
299 | if test "x$enableval" = xno; then |
|
|
300 | TCP=0 |
|
|
301 | fi |
|
|
302 | ) |
|
|
303 | if test "x$TCP" = x1; then |
275 | AC_DEFINE_UNQUOTED(ENABLE_TCP, 1, [TCP protocol support.]) |
304 | AC_DEFINE_UNQUOTED(ENABLE_TCP, 1, [TCP protocol support.]) |
|
|
305 | fi |
|
|
306 | |
|
|
307 | HTTP=1 |
|
|
308 | AC_ARG_ENABLE(http-proxy, |
|
|
309 | [AS_HELP_STRING(--disable-http-proxy,enable http proxy connect support (default enabled).)], |
|
|
310 | if test "x$enableval" = xno; then |
|
|
311 | HTTP=0 |
|
|
312 | fi |
276 | ) |
313 | ) |
|
|
314 | if test "x$HTTP" = x1; then |
|
|
315 | AC_DEFINE_UNQUOTED(ENABLE_HTTP_PROXY, 1, [http proxy connect support.]) |
|
|
316 | fi |
277 | |
317 | |
278 | AC_ARG_ENABLE(dns, |
318 | AC_ARG_ENABLE(dns, |
279 | [AS_HELP_STRING(--enable-dns,enable dns tunnel protocol support (DOES NOT WORK).)], |
319 | [AS_HELP_STRING(--enable-dns,enable dns tunnel protocol support (default disabled).)], |
280 | [ |
320 | [ |
281 | AC_CHECK_HEADER(gmp.h,,[AC_MSG_ERROR([gmp.h not found, required for --enable-dns])]) |
321 | AC_CHECK_HEADER(gmp.h,,[AC_MSG_ERROR([gmp.h not found, required for --enable-dns])]) |
282 | AC_CHECK_LIB(gmp,main,,[AC_MSG_ERROR([libgmp not found, required for --enable-dns])]) |
322 | AC_CHECK_LIB(gmp,main,,[AC_MSG_ERROR([libgmp not found, required for --enable-dns])]) |
283 | |
323 | |
284 | AC_DEFINE_UNQUOTED(ENABLE_DNS, 1, [DNS tunnel protocol support.]) |
324 | AC_DEFINE_UNQUOTED(ENABLE_DNS, 1, [DNS tunnel protocol support.]) |
285 | ] |
325 | ] |
286 | ) |
326 | ) |
287 | |
327 | |
288 | AC_ARG_ENABLE(http-proxy, |
328 | RSA=3072 |
289 | [AS_HELP_STRING(--enable-http-proxy,enable http proxy connect support (default disabled).)], |
329 | AC_ARG_ENABLE(rsa-length, |
290 | AC_DEFINE_UNQUOTED(ENABLE_HTTP_PROXY, 1, [http proxy connect support.]) |
330 | [AS_HELP_STRING(--enable-rsa-length=BITS,[ |
|
|
331 | use BITS rsa keys (default 3072). Allowed values are 2048-10240.])], |
|
|
332 | RSA=$enableval |
291 | ) |
333 | ) |
|
|
334 | AC_DEFINE_UNQUOTED(RSABITS, $RSA, [Size of RSA keys.]) |
292 | |
335 | |
293 | HMAC=12 |
336 | HMACSIZE=12 |
294 | AC_ARG_ENABLE(hmac-length, |
337 | AC_ARG_ENABLE(hmac-length, |
295 | [AS_HELP_STRING(--enable-hmac-length=BYTES,[ |
338 | [AS_HELP_STRING(--enable-hmac-length=BYTES,[ |
296 | use a hmac of length BYTES bytes (default 12). Allowed values are 4, 8, 12, 16.])], |
339 | use a hmac of length BYTES bytes (default 12). Allowed values are 4, 8, 12, 16.])], |
297 | HMAC=$enableval |
340 | HMACSIZE=$enableval |
298 | ) |
341 | ) |
299 | AC_DEFINE_UNQUOTED(HMACLENGTH, $HMAC, [Size of HMAC in each packet in bytes.]) |
342 | AC_DEFINE_UNQUOTED(HMACLENGTH, $HMACSIZE, [Size of HMAC in each packet in bytes.]) |
300 | |
|
|
301 | RAND=8 |
|
|
302 | AC_ARG_ENABLE(rand-length, |
|
|
303 | [AS_HELP_STRING(--enable-rand-length=BYTES, |
|
|
304 | [use BYTES bytes of extra randomness (default 8). Allowed values are 0, 4, 8.])], |
|
|
305 | RAND=$enableval |
|
|
306 | ) |
|
|
307 | AC_DEFINE_UNQUOTED(RAND_SIZE, $RAND, [Add this many bytes of randomness to each packet.]) |
|
|
308 | |
343 | |
309 | MTU=1500 |
344 | MTU=1500 |
310 | AC_ARG_ENABLE(mtu, |
345 | AC_ARG_ENABLE(max-mtu, |
311 | [AS_HELP_STRING(--enable-max-mtu=BYTES,enable mtu sizes upto BYTES bytes (default 1500). Use 9100 for jumbogram support.)], |
346 | [AS_HELP_STRING(--enable-max-mtu=BYTES,enable mtu sizes upto BYTES bytes (default 1500). Use 9100 for jumbogram support.)], |
312 | MTU=$enableval |
347 | MTU=$enableval |
313 | ) |
348 | ) |
314 | AC_DEFINE_UNQUOTED(MAX_MTU, $MTU + 14, [Maximum MTU supported.]) |
349 | AC_DEFINE_UNQUOTED(MAX_MTU, ($MTU + 14), [Maximum MTU supported.]) |
315 | |
350 | |
316 | COMPRESS=1 |
351 | COMPRESS=1 |
317 | AC_ARG_ENABLE(compression, |
352 | AC_ARG_ENABLE(compression, |
318 | [AS_HELP_STRING(--disable-compression,Disable compression support.)], |
353 | [AS_HELP_STRING(--disable-compression,Disable compression support.)], |
319 | if test "x$enableval" = xno; then |
354 | if test "x$enableval" = xno; then |
320 | COMPRESS=0 |
355 | COMPRESS=0 |
321 | fi |
356 | fi |
322 | ) |
357 | ) |
323 | AC_DEFINE_UNQUOTED(ENABLE_COMPRESSION, $COMPRESS, [Enable compression support.]) |
358 | AC_DEFINE_UNQUOTED(ENABLE_COMPRESSION, $COMPRESS, [Enable compression support.]) |
324 | |
359 | |
325 | CIPHER=bf_cbc |
360 | CIPHER=aes_128_ctr |
326 | AC_ARG_ENABLE(cipher, |
361 | AC_ARG_ENABLE(cipher, |
327 | [AS_HELP_STRING(--enable-cipher,[ |
362 | [AS_HELP_STRING(--enable-cipher=CIPHER,[ |
328 | Select the symmetric cipher (default "bf"). |
363 | Select the symmetric cipher (default "aes-128"). |
329 | Must be one of "bf" (blowfish), "aes-128" (rijndael), "aes-192" or "aes-256".])], |
364 | Must be one of "aes-128" (rijndael), "aes-192", or "aes-256".])], |
330 | if test "x$enableval" = xbf ; then CIPHER=bf_cbc ; fi |
365 | #if test "x$enableval" = xbf ; then CIPHER=bf_ctr ; fi |
331 | if test "x$enableval" = xaes-128; then CIPHER=aes_128_cbc; fi |
366 | if test "x$enableval" = xaes-128 ; then CIPHER=aes_128_ctr ; fi |
332 | if test "x$enableval" = xaes-192; then CIPHER=aes_192_cbc; fi |
367 | if test "x$enableval" = xaes-192 ; then CIPHER=aes_192_ctr ; fi |
333 | if test "x$enableval" = xaes-256; then CIPHER=aes_256_cbc; fi |
368 | if test "x$enableval" = xaes-256 ; then CIPHER=aes_256_ctr ; fi |
|
|
369 | #if test "x$enableval" = xcamellia-128; then CIPHER=camellia_128_ctr; fi |
|
|
370 | #if test "x$enableval" = xcamellia-256; then CIPHER=camellia_256_ctr; fi |
334 | ) |
371 | ) |
335 | AC_DEFINE_UNQUOTED(ENABLE_CIPHER, EVP_${CIPHER}, [Select the symmetric cipher to use.]) |
372 | AC_DEFINE_UNQUOTED(ENABLE_CIPHER, EVP_${CIPHER}, [Select the symmetric cipher to use.]) |
336 | |
373 | |
337 | DIGEST=sha1 |
374 | HMAC=sha1 |
338 | AC_ARG_ENABLE(digest, |
375 | AC_ARG_ENABLE(hmac-digest, |
339 | [AS_HELP_STRING(--enable-digest,[ |
376 | [AS_HELP_STRING(--enable-hmac-digest=HMAC,[ |
340 | Select the digets algorithm to use (default "sha1"). Must be one of |
377 | Select the HMAC digest algorithm to use (default "sha1"). Must be one of |
341 | "sha1", "ripemd160", "md5" or "md4" (insecure).])], |
378 | "sha512", "sha256", "sha1", "ripemd160", "whirlpool".])], |
|
|
379 | if test "x$enableval" = xwhirlpool; then HMAC=whirlpool; fi |
|
|
380 | if test "x$enableval" = xsha512 ; then HMAC=sha512 ; fi |
|
|
381 | if test "x$enableval" = xsha256 ; then HMAC=sha256 ; fi |
342 | if test "x$enableval" = xsha1 ; then DIGEST=sha1 ; fi |
382 | if test "x$enableval" = xsha1 ; then HMAC=sha1 ; fi |
343 | if test "x$enableval" = xripemd160; then DIGEST=ripemd160; fi |
383 | if test "x$enableval" = xripemd160; then HMAC=ripemd160; fi |
|
|
384 | ) |
|
|
385 | AC_DEFINE_UNQUOTED(ENABLE_HMAC, EVP_${HMAC}, [Select the HMAC digest algorithm to use.]) |
|
|
386 | |
|
|
387 | AUTH=sha512 |
|
|
388 | AC_ARG_ENABLE(auth-digest, |
|
|
389 | [AS_HELP_STRING(--enable-auth-digest=DIGEST,[ |
|
|
390 | Select the hmac algorithm to use (default "sha512"). Must be one of |
|
|
391 | "sha512", "sha256", "whirlpool".])], |
|
|
392 | if test "x$enableval" = xwhirlpool; then AUTH=whirlpool; fi |
344 | if test "x$enableval" = xmd5 ; then DIGEST=md5 ; fi |
393 | if test "x$enableval" = xsha512 ; then AUTH=sha512 ; fi |
345 | if test "x$enableval" = xmd4 ; then DIGEST=md4 ; fi |
394 | if test "x$enableval" = xsha256 ; then AUTH=sha256 ; fi |
346 | ) |
395 | ) |
347 | AC_DEFINE_UNQUOTED(ENABLE_DIGEST, EVP_${DIGEST}, [Select the digest algorithm to use.]) |
396 | AC_DEFINE_UNQUOTED(ENABLE_AUTH, EVP_${AUTH}, [Select the auth digest algorithm to use.]) |
348 | |
397 | |
349 | if $CXX -v --help 2>&1 | grep -q fno-rtti; then |
398 | if $CXX -v --help 2>&1 | grep -q fno-rtti; then |
350 | CXXFLAGS="$CXXFLAGS -fno-rtti" |
399 | CXXFLAGS="$CXXFLAGS -fno-rtti" |
351 | fi |
400 | fi |
352 | |
401 | |
353 | if $CXX -v --help 2>&1 | grep -q fexceptions; then |
402 | #if $CXX -v --help 2>&1 | grep -q fexceptions; then |
354 | CXXFLAGS="$CXXFLAGS -fno-exceptions" |
403 | # CXXFLAGS="$CXXFLAGS -fno-exceptions" |
355 | fi |
404 | #fi |
|
|
405 | |
|
|
406 | LIBS="$EXTRA_LIBS $LIBS" |
356 | |
407 | |
357 | dnl if $CXX -v --help 2>&1 | grep -q ffunction-sections; then |
408 | dnl if $CXX -v --help 2>&1 | grep -q ffunction-sections; then |
358 | dnl CXXFLAGS="$CXXFLAGS -ffunction-sections" |
409 | dnl CXXFLAGS="$CXXFLAGS -ffunction-sections" |
359 | dnl fi |
410 | dnl fi |
360 | dnl |
411 | dnl |
361 | dnl if $LD -v --help 2>&1 | grep -q gc-sections; then |
412 | dnl if $LD -v --help 2>&1 | grep -q gc-sections; then |
362 | dnl LDFLAGS="$LDFLAGS -Wl,--gc-sections" |
413 | dnl LDFLAGS="$LDFLAGS -Wl,--gc-sections" |
363 | dnl fi |
414 | dnl fi |
364 | |
415 | |
365 | AC_CONFIG_COMMANDS_POST([ |
416 | AC_SUBST(INCLUDES) |
|
|
417 | |
|
|
418 | AC_CONFIG_FILES([Makefile po/Makefile.in |
|
|
419 | src/Makefile |
|
|
420 | doc/Makefile |
|
|
421 | lib/Makefile |
|
|
422 | m4/Makefile |
|
|
423 | ]) |
|
|
424 | AC_OUTPUT |
366 | |
425 | |
367 | echo |
426 | echo |
368 | echo "***" |
427 | echo "***" |
369 | echo "*** Configuration Summary" |
428 | echo "*** Configuration Summary" |
370 | echo "***" |
429 | echo "***" |
371 | echo "*** Kernel Iface: $IFTYPE/$IFSUBTYPE" |
430 | echo "*** Kernel Iface: $IFTYPE/$IFSUBTYPE" |
|
|
431 | echo "*** RSA size: $RSA" |
372 | echo "*** Cipher used: $CIPHER" |
432 | echo "*** Cipher used: $CIPHER" |
373 | echo "*** Digest used: $DIGEST" |
433 | echo "*** Digest used: $DIGEST" |
|
|
434 | echo "*** Authdigest: $AUTH" |
374 | echo "*** HMAC length: $HMAC" |
435 | echo "*** HMAC length: $HMAC" |
375 | echo "*** RAND used: $RAND" |
|
|
376 | echo "*** Max. MTU: $MTU" |
436 | echo "*** Max. MTU: $MTU" |
377 | echo "*** Compression: $COMPRESS" |
|
|
378 | |
437 | |
379 | if test "x$DIGEST" = xmd4; then |
|
|
380 | echo "***" |
438 | echo "***" |
381 | echo "*** WARNING: The digest you have chosen ($DIGEST) is known to be insecure" |
439 | echo "*** Enable options:" |
382 | fi |
440 | grep ENABLE_ config.h | sed -e 's/^/*** /' |
383 | |
441 | |
384 | if test "$HMAC" -lt 12; then |
442 | if test "$HMACSIZE" -lt 12; then |
385 | echo "***" |
443 | echo "***" |
386 | echo "*** WARNING: The hmac length you have chosen ($HMAC) is probably insecure" |
444 | echo "*** WARNING: The hmac length you have chosen ($HMACSIZE) is quite insecure" |
387 | fi |
445 | fi |
388 | |
446 | |
389 | if test "$RAND" -lt 8; then |
|
|
390 | echo "***" |
447 | echo "***" |
391 | echo "*** WARNING: The random prefix you have chosen ($RAND) is probably insecure" |
|
|
392 | fi |
|
|
393 | |
|
|
394 | echo "***" |
|
|
395 | |
|
|
396 | echo |
448 | echo |
397 | |
449 | |
398 | ]) |
450 | if pkg-config --exists 'libcrypto >= 1.1 libcrypto < 2.0'; then |
|
|
451 | cat <<EOF |
|
|
452 | @<:@33m |
|
|
453 | *** |
|
|
454 | *** WARNING WARNING WARNING WARNING WARNING WARNING WARNING |
|
|
455 | *** |
|
|
456 | *** You seem to configure gvpe with OpenSSL 1.1 or newer. |
|
|
457 | *** While this probably compiles, please note that this is not only |
|
|
458 | *** unsupported, but also discouraged. |
|
|
459 | *** |
|
|
460 | *** It is recommended to use either OpenSSL 1.0, as long as that is still |
|
|
461 | *** supported, or LibreSSL (https://www.libressl.org/). |
|
|
462 | *** |
|
|
463 | *** This is not a political issue - while porting GVPE to the newer |
|
|
464 | *** OpenSSL 1.1 API, I encountered two incompatible API changes that were |
|
|
465 | *** not documented, were not caught while compiling but caused security |
|
|
466 | *** issues. When reported, the reaction of the OpenSSL developers was to |
|
|
467 | *** update the documentation. |
|
|
468 | *** |
|
|
469 | *** As a result, I lost all confidence in the ability and desire of |
|
|
470 | *** OpenSSL developers to create a safe API, and would highly recommend |
|
|
471 | *** switching to LibreSSL which explicitly avoids such braking changes. |
|
|
472 | *** |
|
|
473 | *** WARNING WARNING WARNING WARNING WARNING WARNING WARNING |
|
|
474 | *** |
|
|
475 | *** Again, do not use OpenSSL 1.1 and complain if stuff breaks. |
|
|
476 | *** You have been warned, but your choice is respected. |
|
|
477 | *** |
|
|
478 | @<:@0m |
399 | |
479 | |
400 | AC_SUBST(INCLUDES) |
480 | EOF |
|
|
481 | fi |
401 | |
482 | |
402 | AC_CONFIG_FILES([Makefile po/Makefile.in |
483 | |
403 | src/Makefile |
|
|
404 | doc/Makefile |
|
|
405 | lib/Makefile |
|
|
406 | m4/Makefile |
|
|
407 | ]) |
|
|
408 | AC_OUTPUT |
|
|