From: Herbert Xu Subject: Re: [PATCH] Revert "crypto: talitos - add IPsec ESN support" Date: Thu, 21 Mar 2013 17:36:49 +0800 Message-ID: <20130321093649.GA26808@gondor.apana.org.au> References: <1363789898-15297-1-git-send-email-horia.geanta@freescale.com> <20130320184634.f1443f3ed23b3c6e8648429e@freescale.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Horia Geanta , linux-crypto@vger.kernel.org, Chaoxing Lin , Steffen Klassert , stable@vger.kernel.org To: Kim Phillips Return-path: Content-Disposition: inline In-Reply-To: <20130320184634.f1443f3ed23b3c6e8648429e@freescale.com> Sender: stable-owner@vger.kernel.org List-Id: linux-crypto.vger.kernel.org On Wed, Mar 20, 2013 at 06:46:34PM -0500, Kim Phillips wrote: > On Wed, 20 Mar 2013 16:31:38 +0200 > Horia Geanta wrote: > > > This reverts commit e763eb699be723fb41af818118068c6b3afdaf8d. > > > > Current IPsec ESN implementation for authencesn(cbc(aes), hmac(sha)) > > (separate encryption and integrity algorithms) does not conform > > to RFC4303. > > > > ICV is generated by hashing the sequence > > SPI, SeqNum-High, SeqNum-Low, IV, Payload > > instead of > > SPI, SeqNum-Low, IV, Payload, SeqNum-High. > > > > Cc: # 3.8, 3.7 > > Reported-by: Chaoxing Lin > > Signed-off-by: Horia Geanta > > --- > > Reviewed-by: Kim Phillips Both patches applied to crypto. Thanks! -- Email: Herbert Xu Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt