#!/usr/bin/env bash # # Copyright (C) 2011-2021 Intel Corporation. All rights reserved. # # Redistribution and use in source and binary forms, with or without # modification, are permitted provided that the following conditions # are met: # # * Redistributions of source code must retain the above copyright # notice, this list of conditions and the following disclaimer. # * Redistributions in binary form must reproduce the above copyright # notice, this list of conditions and the following disclaimer in # the documentation and/or other materials provided with the # distribution. # * Neither the name of Intel Corporation nor the names of its # contributors may be used to endorse or promote products derived # from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS # "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT # LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR # A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT # OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT # LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, # DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY # THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT # (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE # OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # # ARG1=${1:-build} project_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" echo "project_dir is $project_dir" sgxssl_dir=$project_dir/sgxssl openssl_out_dir=$sgxssl_dir/openssl_source openssl_ver_name=openssl-3.0.17 intel_sgx_ssl_url=https://github.com/intel/intel-sgx-ssl support_tls_branch=support_tls_openssl3 build_script=$sgxssl_dir/Linux/build_openssl.sh server_url_path=https://www.openssl.org/source full_openssl_url=$server_url_path/$openssl_ver_name.tar.gz full_openssl_url_old=$server_url_path/old/3.0.17/$openssl_ver_name.tar.gz FileExists() { pushd $sgxssl_dir/Linux/ if [ $SGX_DEBUG == 0 ] ; then echo "build release mode openssl" make clean sgxssl_no_mitigation else echo "build debug mode openssl" make clean sgxssl_no_mitigation DEBUG=1 fi echo "build sgxssl completed" popd } debug=false if [ $debug == true ] ; then read -n 1 -p "download souce code only, because we need to build ourselves" fi openssl_chksum=dfdd77e4ea1b57ff3a6dbde6b0bdc3f31db5ac99e7fdd4eaf9e1fbb6ec2db8ce rm -f check_sum_openssl.txt if [ ! -f $build_script ]; then git clone $intel_sgx_ssl_url -b $support_tls_branch $sgxssl_dir || exit 1 fi if [ ! -f $openssl_out_dir/$openssl_ver_name.tar.gz ]; then wget $full_openssl_url_old -P $openssl_out_dir || wget $full_openssl_url -P $openssl_out_dir || exit 1 sha256sum $openssl_out_dir/$openssl_ver_name.tar.gz > $sgxssl_dir/check_sum_openssl.txt echo "downloading OPENSSL source code now..." grep $openssl_chksum $sgxssl_dir/check_sum_openssl.txt if [ $? -ne 0 ]; then echo "File $openssl_out_dir/$openssl_ver_name.tar.gz checksum failure" rm -f $openssl_out_dir/$openssl_ver_name.tar.gz exit -1 fi fi if [ "$1" = "nobuild" ]; then exit 0 fi if [ $debug == false ] ; then echo "only when debug is turned off, can script go here" FileExists echo "endof of build sgxssl" && exit 0 fi echo "end of script"