set FIPS allow before initialising ctx
diff --git a/ssl/s3_srvr.c b/ssl/s3_srvr.c index 8600d06..197a498 100644 --- a/ssl/s3_srvr.c +++ b/ssl/s3_srvr.c
@@ -1921,10 +1921,10 @@ j=0; for (num=2; num > 0; num--) { - EVP_DigestInit_ex(&md_ctx,(num == 2) - ?s->ctx->md5:s->ctx->sha1, NULL); EVP_MD_CTX_set_flags(&md_ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); + EVP_DigestInit_ex(&md_ctx,(num == 2) + ?s->ctx->md5:s->ctx->sha1, NULL); EVP_DigestUpdate(&md_ctx,&(s->s3->client_random[0]),SSL3_RANDOM_SIZE); EVP_DigestUpdate(&md_ctx,&(s->s3->server_random[0]),SSL3_RANDOM_SIZE); EVP_DigestUpdate(&md_ctx,&(d[4]),n);