Thread (11 messages) 11 messages, 4 authors, 2016-01-16

Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type

From: David Woodhouse <hidden>
Date: 2016-01-13 15:06:45
Also in: linux-api, lkml

On Wed, 2016-01-13 at 06:05 -0800, Tadeusz Struk wrote:
I agree, ideally keyctl should do the job for all the cases and
request_key() should just return a key data.
No, you can NOT RELY ON HAVING THE KEY DATA. It might be in hardware.
You might have something which will perform sign/verify/encrypt/decrypt
operations *with* the key at your request, but which can never just
*give* you the key.

Any crypto API which relies on *having* the key is fundamentally wrong.

-- 
dwmw2

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help