Received: by 2002:a4a:311b:0:0:0:0:0 with SMTP id k27-v6csp4806921ooa; Tue, 14 Aug 2018 10:49:13 -0700 (PDT) X-Google-Smtp-Source: AA+uWPx0ym/QVfdzF2PUGnv5CAG0fHbyBrojDkfInRH3knCae3p+epdKGCoUh1moks3OwRWbvroB X-Received: by 2002:a65:5b8e:: with SMTP id i14-v6mr22249358pgr.242.1534268953127; Tue, 14 Aug 2018 10:49:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1534268953; cv=none; d=google.com; s=arc-20160816; b=Oet1l3eu9PXhrtadvUwiuqS7R3Z+gABw9at2da7zTCXc5MS5gOT+KBeAlvpVNNJbrV 6YTj7m+3OILZROYy567AS+AHPv/GykAobrFawRuoDFW/8RoDzR8dSuXrX+RuuSu9E1Ut jA3USyX0OpKVz0LwjWhPGxGirqiJrJ/G9FtIcWkV0WnNJ3aKsBbXTRZQAJPW4DTsI6Mc YSeep5l/OoYadB1ZVwvAJ+AmYRAn31+eiTOxtCpT2Q4QPdmYAYrIjdaqZOfHgwycLnao 4Jz7xEuWLvhIpe7cc9xpzqFGeoFuU7stUCE09DQHoTZ2GBOdPMu+PuqN0qwyVZFoPOkI PhwQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=jKZSdYmIXkfICT7qBBPiEvTK39+nVZwXuI0ssstB7tE=; b=ZcbpuFGA4nSCekt+2fUiKrSftQulIxXSUntzj9E48/RL4ZiTOdTWT10RznU1YTQl6o VSV+PzxTa1aAAvn87udE/A5JoTPA0XBfcCyPSHV8Tn1sVeD3SrlmfCWnnIMybhfAgjNp yr1+g8eAguH5e1O885+gwWIH62m1jGjeqputW7U2jZxkpGozu2iTD1LuCAd0BACEennB z9HK+1SZHjNVaR3ZkZNjLl/5mA3h7kVBU9ZU4IuaRsyqtMNc/r22HwgZ2eFMTHLQ0NkS Dk/Q792H7QVgPR/Q+aX11Q0tPY2wjDIqL184+j3J+N4KHAVlpKS/wgqkhJlvWPaqamYN gvAQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e2-v6si21474485pgl.4.2018.08.14.10.48.58; Tue, 14 Aug 2018 10:49:13 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2403796AbeHNUfY (ORCPT + 99 others); Tue, 14 Aug 2018 16:35:24 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:60890 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2390379AbeHNUfX (ORCPT ); Tue, 14 Aug 2018 16:35:23 -0400 Received: from localhost (unknown [194.244.16.108]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 614ECD08; Tue, 14 Aug 2018 17:47:11 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Thomas Egerer , Herbert Xu , "David S. Miller" , Yongqin Liu Subject: [PATCH 4.4 03/43] ipv4+ipv6: Make INET*_ESP select CRYPTO_ECHAINIV Date: Tue, 14 Aug 2018 19:17:39 +0200 Message-Id: <20180814171517.268645279@linuxfoundation.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180814171517.014285600@linuxfoundation.org> References: <20180814171517.014285600@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Thomas Egerer commit 32b6170ca59ccf07d0e394561e54b2cd9726038c upstream. The ESP algorithms using CBC mode require echainiv. Hence INET*_ESP have to select CRYPTO_ECHAINIV in order to work properly. This solves the issues caused by a misconfiguration as described in [1]. The original approach, patching crypto/Kconfig was turned down by Herbert Xu [2]. [1] https://lists.strongswan.org/pipermail/users/2015-December/009074.html [2] http://marc.info/?l=linux-crypto-vger&m=145224655809562&w=2 Signed-off-by: Thomas Egerer Acked-by: Herbert Xu Signed-off-by: David S. Miller Cc: Yongqin Liu Signed-off-by: Greg Kroah-Hartman --- net/ipv4/Kconfig | 1 + net/ipv6/Kconfig | 1 + 2 files changed, 2 insertions(+) --- a/net/ipv4/Kconfig +++ b/net/ipv4/Kconfig @@ -354,6 +354,7 @@ config INET_ESP select CRYPTO_CBC select CRYPTO_SHA1 select CRYPTO_DES + select CRYPTO_ECHAINIV ---help--- Support for IPsec ESP. --- a/net/ipv6/Kconfig +++ b/net/ipv6/Kconfig @@ -69,6 +69,7 @@ config INET6_ESP select CRYPTO_CBC select CRYPTO_SHA1 select CRYPTO_DES + select CRYPTO_ECHAINIV ---help--- Support for IPsec ESP.