Re: [GIT PULL] crypto: Add Kerberos crypto lib
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2025-03-02 06:10:30
Also in:
linux-crypto, linux-fsdevel, linux-nfs, lkml
On Fri, Feb 28, 2025 at 09:55:47AM +0000, David Howells wrote:
Hi Herbert,
Could you pull this into the crypto tree please? It does a couple of
things:
(1) Provide an AEAD crypto driver, krb5enc, that mirrors the authenc
driver, but that hashes the plaintext, not the ciphertext. This was
made a separate module rather than just being a part of the authenc
driver because it has to do all of the constituent operations in the
opposite order - which impacts the async op handling.
Testmgr data is provided for AES+SHA2 and Camellia combinations of
authenc and krb5enc used by the krb5 library. AES+SHA1 is not
provided as the RFCs don't contain usable test vectors.
(2) Provide a Kerberos 5 crypto library. This is an extract from the
sunrpc driver as that code can be shared between sunrpc/nfs and
rxrpc/afs. This provides encryption, decryption, get MIC and verify
MIC routines that use and wrap the crypto functions, along with some
functions to provide layout management.
This supports AES+SHA1, AES+SHA2 and Camellia encryption types.
Self-testing is provided that goes further than is possible with
testmgr, doing subkey derivation as well.
The patches were previously posted here:
https://lore.kernel.org/r/20250203142343.248839-1-dhowells@redhat.com/ (local)
as part of a larger series, but the networking guys would prefer these to
go through the crypto tree. If you want them reposting independently, I
can do that.I tried pulling it but it's not based on the cryptodev tree so it will create a mess when I push this upstream. If you want me to pull it through cryptodev please rebase it on my tree. Thanks, -- Email: Herbert Xu [off-list ref] Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt