Thread (5 messages) 5 messages, 3 authors, 2018-10-17

Re: [PATCH] net-xfrm: add build time cfg option to PF_KEY SHA256 to use RFC4868-compliant truncation

From: Lorenzo Colitti <hidden>
Date: 2018-10-16 16:04:09

On Tue, Oct 16, 2018 at 5:06 PM Maciej Żenczykowski
[off-list ref] wrote:
+config XFRM_HMAC_SHA256_RFC4868
+       bool "Strict RFC4868 hmac(sha256) 128-bit truncation"
+       depends on XFRM_ALGO
+       default n
+       ---help---
+         Support strict RFC4868 hmac(sha256) 128-bit truncation
+         (default on Android) instead of the default 96-bit Linux truncation.
Not sure it's worth mentioning Android here, given that other
contributors from other organizations have attempted to change this as
well.
        .uinfo = {
                .auth = {
+#if IS_ENABLED(CONFIG_XFRM_HMAC_SHA256_RFC4868)
+                       .icv_truncbits = 128,
+#else
                        .icv_truncbits = 96,
+#endif
Also, consider adding a Tested: line saying that this allows
pf_key_test.py to pass on upstream kernels.

Other than that,

Acked-By: Lorenzo Colitti <redacted>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help