2009-11-25 10:58:38

by Martin Willi

[permalink] [raw]
Subject: [PATCH] xfrm: Add SHA384 and SHA512 HMAC authentication algorithms to XFRM

These algorithms use a truncation of 192/256 bits, as specified
in RFC4868.

Signed-off-by: Martin Willi <[email protected]>
---
net/xfrm/xfrm_algo.c | 34 ++++++++++++++++++++++++++++++++++
1 files changed, 34 insertions(+), 0 deletions(-)

diff --git a/net/xfrm/xfrm_algo.c b/net/xfrm/xfrm_algo.c
index faf54c6..480afda 100644
--- a/net/xfrm/xfrm_algo.c
+++ b/net/xfrm/xfrm_algo.c
@@ -200,6 +200,40 @@ static struct xfrm_algo_desc aalg_list[] = {
}
},
{
+ .name = "hmac(sha384)",
+
+ .uinfo = {
+ .auth = {
+ .icv_truncbits = 192,
+ .icv_fullbits = 384,
+ }
+ },
+
+ .desc = {
+ .sadb_alg_id = SADB_X_AALG_SHA2_384HMAC,
+ .sadb_alg_ivlen = 0,
+ .sadb_alg_minbits = 384,
+ .sadb_alg_maxbits = 384
+ }
+},
+{
+ .name = "hmac(sha512)",
+
+ .uinfo = {
+ .auth = {
+ .icv_truncbits = 256,
+ .icv_fullbits = 512,
+ }
+ },
+
+ .desc = {
+ .sadb_alg_id = SADB_X_AALG_SHA2_512HMAC,
+ .sadb_alg_ivlen = 0,
+ .sadb_alg_minbits = 512,
+ .sadb_alg_maxbits = 512
+ }
+},
+{
.name = "hmac(rmd160)",
.compat = "rmd160",

--
1.6.3.3



2009-11-25 12:11:40

by Herbert Xu

[permalink] [raw]
Subject: Re: [PATCH] xfrm: Add SHA384 and SHA512 HMAC authentication algorithms to XFRM

On Wed, Nov 25, 2009 at 11:58:39AM +0100, Martin Willi wrote:
> These algorithms use a truncation of 192/256 bits, as specified
> in RFC4868.
>
> Signed-off-by: Martin Willi <[email protected]>

Acked-by: Herbert Xu <[email protected]>
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <[email protected]>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

2009-11-25 23:49:02

by David Miller

[permalink] [raw]
Subject: Re: [PATCH] xfrm: Add SHA384 and SHA512 HMAC authentication algorithms to XFRM

From: Herbert Xu <[email protected]>
Date: Wed, 25 Nov 2009 20:11:40 +0800

> On Wed, Nov 25, 2009 at 11:58:39AM +0100, Martin Willi wrote:
>> These algorithms use a truncation of 192/256 bits, as specified
>> in RFC4868.
>>
>> Signed-off-by: Martin Willi <[email protected]>
>
> Acked-by: Herbert Xu <[email protected]>

Applied to net-next-2.6