Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp3489394yba; Tue, 7 May 2019 02:00:05 -0700 (PDT) X-Google-Smtp-Source: APXvYqzoqC+8hmzTcfsuqLNLaFR9JQd0mq5dUv16p7kJ+jULiFLFhqhlHt1A3A+zz81pzKWG4dhg X-Received: by 2002:a17:902:b20f:: with SMTP id t15mr39086060plr.341.1557219604859; Tue, 07 May 2019 02:00:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1557219604; cv=none; d=google.com; s=arc-20160816; b=FauQbHhkCu3l8j0RiB23pwhK44nY4Q7rmEfngGNWbSIGPIIsV21QzW5ELpQr9mr9Iz pIyd5omx3Q03f49D7Utu7MWzzem6vUlajiLnWAVLM6zCRDRXA8Y5pwNdbiMplMQKmz8L avD/x0vxrXYK5efgHnVjC9OUUKBn6+O6t8x7tMXKbOr6pZ8Rf3fop2C/QT9uU1Tfu5NW BolLmPjdcc/ouqJdGn0GUskQkI6wdAefzaH/jaIAp/COIqiuxYLs7qyP/AeA6AgP1m5J HY+Omr5lD7gb9vmOb0sIQPBrOtPJzaboVS7CXrKQ+HKaUaelUmPXePvj3bTXF/dTKPvs Eukw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:subject:content-transfer-encoding :mime-version:user-agent:organization:references:in-reply-to:date:cc :to:from:message-id; bh=LxtJOYW2c4FE4xODjJVSnVa1UQa1cBTp86RBsdxILUs=; b=XFoW2gcHJ3PRYGXsqd8tp5RdGKbyy6xg/Xh2M6SFpTdJ7VDvxq5vTD1BLRjfHhFbRY plj3pDrERM34cWBSXM6huXZ6ENeRLdtKm/4syehNJk1bv1xVaRbfc5FCUc3puImywynV KT3IURVEwPAntxoMXMLaya25rgsqHGle8tYwwPbrLeDdhZGWj4I67RFLmCd0Rb9O+d5L FXswHv06sYKfrvJo5yj4bACim+rTAGWTe+wtJnIZmS2aZsjnMNbtDTCnNCYTQg1UQehE 38L/AunqcoRRtVyzen1wMVopHlYatEaWf6aWC9tBA/gfXtd9PmaRP3KzOIShf2JJMGqV 93jA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j15si3722774pll.40.2019.05.07.01.59.43; Tue, 07 May 2019 02:00:04 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726873AbfEGI7N (ORCPT + 99 others); Tue, 7 May 2019 04:59:13 -0400 Received: from ou.quest-ce.net ([195.154.187.82]:36007 "EHLO ou.quest-ce.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726072AbfEGI7M (ORCPT ); Tue, 7 May 2019 04:59:12 -0400 X-Greylist: delayed 2370 seconds by postgrey-1.27 at vger.kernel.org; Tue, 07 May 2019 04:59:11 EDT Received: from [2a01:e35:39f2:1220:2452:dd6c:fe2f:be2c] (helo=opteyam2) by ou.quest-ce.net with esmtpsa (TLS1.1:RSA_AES_256_CBC_SHA1:256) (Exim 4.80) (envelope-from ) id 1hNvK6-0006Hu-SW; Tue, 07 May 2019 10:19:39 +0200 Message-ID: From: Yann Droneaud To: Stephan =?ISO-8859-1?Q?M=FCller?= , Herbert Xu Cc: linux-crypto@vger.kernel.org Date: Tue, 07 May 2019 10:19:38 +0200 In-Reply-To: <1978979.Zxv6YQyJUk@positron.chronox.de> References: <1852500.fyBc0DU23F@positron.chronox.de> <5352150.0CmBXKFm2E@positron.chronox.de> <20190503014241.cy35pjinezhapga7@gondor.apana.org.au> <1978979.Zxv6YQyJUk@positron.chronox.de> Organization: OPTEYA Content-Type: text/plain; charset="UTF-8" User-Agent: Evolution 3.32.1 (3.32.1-1.fc30) MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SA-Exim-Connect-IP: 2a01:e35:39f2:1220:2452:dd6c:fe2f:be2c X-SA-Exim-Mail-From: ydroneaud@opteya.com X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ou.quest-ce.net X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham version=3.3.2 Subject: Re: [PATCH v4] crypto: DRBG - add FIPS 140-2 CTRNG for noise source X-SA-Exim-Version: 4.2.1 (built Mon, 26 Dec 2011 16:24:06 +0000) X-SA-Exim-Scanned: Yes (on ou.quest-ce.net) Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org Hi Le vendredi 03 mai 2019 à 21:58 +0200, Stephan Müller a écrit : > > FIPS 140-2 section 4.9.2 requires a continuous self test of the noise > source. Up to kernel 4.8 drivers/char/random.c provided this continuous > self test. Afterwards it was moved to a location that is inconsistent > with the FIPS 140-2 requirements. > Could you list the commit that move the self test and add that information in the commit message. > Thus, the FIPS 140-2 CTRNG is added to the DRBG when it obtains the > seed. This patch resurrects the function drbg_fips_continous_test that > existed some time ago and applies it to the noise sources. > Please identify the commit it was resurrected from, for traceability purpose. Regards. -- Yann Droneaud OPTEYA