2024-05-10 13:14:44

by Marek Behún

[permalink] [raw]
Subject: Is akcipher ready for userspace?

Hello Herbert,

back in 2019 you wrote that akcipher is still in a state of flux and
not ready to be exposed to userspace via AF_ALG [1].

Has this changed since then?

I am asking because I am implementing another driver [2] for a device
which allows for signing messages with an ECDSA private key securely
stored inside the device, and Greg asks again [3] for this to be
exposed to userspace via a dedicated kernel API, instead of
debugfs.

Back in 2019 when we needed this for the turris-mox-rwtm driver, I
implemented it via debugfs because akcipher was not ready.

Thanks.

Marek

[1] https://www.spinics.net/lists/linux-crypto/msg38388.html
[2] https://lore.kernel.org/soc/[email protected]/T/
[3] https://lore.kernel.org/soc/2024051042-unbuckled-barometer-1099@gregkh/