Thread (6 messages) 6 messages, 4 authors, 2018-11-09

Re: [PATCH] crypto: mark cts(cbc(aes)) as FIPS allowed

From: Gilad Ben-Yossef <gilad@benyossef.com>
Date: 2018-11-05 09:18:14
Also in: lkml

Hi Stephan,

On Mon, Nov 5, 2018 at 10:50 AM Stephan Mueller [off-list ref] wrote:
Am Sonntag, 4. November 2018, 11:05:24 CET schrieb Gilad Ben-Yossef:

Hi Gilad,
quoted
As per Sp800-38A addendum from Oct 2010[1], cts(cbc(aes)) is
allowed as a FIPS mode algorithm. Mark it as such.

[1] https://csrc.nist.gov/publications/detail/sp/800-38a/addendum/final
There are several types of CTS approaches. Only three of those are listed in
the SP800-38A addendum. The source code only refers to some RFCs.

Did you check whether the CTS implementation matches one or more of the types
listed in the addendum? If yes, may I suggest to add a small statement in the
code noting this fact?
Yes, AFAIK the software implements CBC-CS3 as described in the document.
You have a very good point about this not document anywhere. I will
send a patch.

While we're at it, does someone find it useful if I implemented the
other two modes?
They are part of the standard as well, although I am not sure that in
itself is sufficient cause.


Gilad

--
Gilad Ben-Yossef
Chief Coffee Drinker

values of β will give rise to dom!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help