Received: by 2002:a05:6a10:9848:0:0:0:0 with SMTP id x8csp4098769pxf; Mon, 29 Mar 2021 22:03:39 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzS4lDV0+0CtTmfP1baKdvPeggx74ktcs3Fk5fAIQ4ofUE9e3ezUHfjGW2UbiHatagKl3e9 X-Received: by 2002:aa7:dd99:: with SMTP id g25mr31203676edv.230.1617080619038; Mon, 29 Mar 2021 22:03:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1617080619; cv=none; d=google.com; s=arc-20160816; b=vKzrO6MYHiPGt79aGaJrMfY3fcTXKWjshYGjuk8hJTYM7IC5pHRSvh1+w1n61ZsUQs 93lR5RZKl+9gzzlp1Mf8jUiEs5H19uoX3HNC/FosB8M1S/4mvPS1YxeViivZKI1pEx3d FTn3sy8E4R2wQrnRVdNBFkmQlDVtkPJWu4KU/oxCAgILn5IaEUYKnXpXNvCKmQjltRHY TpQDT5ALg/yHt4XYMAglqFWYMzjpiDMZOSFG3ENGSSDLYlCu6tPgfzN8nrGgw3sfd398 jDpJFwjyHeTAKmyFRUxb+d9VrYoOF67TBbeo9YdqnApBbJ4jBdBA3MCdwhC3E+urb2lH cDww== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:in-reply-to:content-disposition :mime-version:references:message-id:subject:cc:to:from:date; bh=9bIcFPZT2S4rt+0+N3PqPj7tqa20vNTe0WODYfzS1Ho=; b=nCxlzx5TzLPhedv55TZFKlXTsikzo5vHRSjJrsm9piB9pk1tzc/MFJN8+g43+yoB2W 4jSbuyyOonlc2/WzP9DyKL6AngFwfHWmWpLL4moX02MlnvdvHaJxUKQcfQ7FHN4EesfQ dp2aCyvvTv+lZD6+2YJWPx6kYh7DV/mYw9okBXGRdwRZ2uPcgNf6AGw9ZS4ykAkQO7q8 SeofLiupvDi7i8FdgdXgDVy5fojPRVkm4jj8kxm/h9IdaU6gQ13Ra1e+PQeG/XqvjpmK inNEus6dONRhSvKDMe2S/7UEJQSnAlgqyZqkTuNJlSIOANI/KGzQ38xPREvjuQqZckma eXBg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id rn17si15885676ejb.183.2021.03.29.22.03.16; Mon, 29 Mar 2021 22:03:39 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230306AbhC3FCi (ORCPT + 99 others); Tue, 30 Mar 2021 01:02:38 -0400 Received: from helcar.hmeau.com ([216.24.177.18]:41010 "EHLO fornost.hmeau.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230180AbhC3FCf (ORCPT ); Tue, 30 Mar 2021 01:02:35 -0400 Received: from gwarestrin.arnor.me.apana.org.au ([192.168.103.7]) by fornost.hmeau.com with smtp (Exim 4.92 #5 (Debian)) id 1lR6WE-0003wq-DN; Tue, 30 Mar 2021 16:02:23 +1100 Received: by gwarestrin.arnor.me.apana.org.au (sSMTP sendmail emulation); Tue, 30 Mar 2021 16:02:22 +1100 Date: Tue, 30 Mar 2021 16:02:22 +1100 From: Herbert Xu To: Randy Dunlap Cc: linux-kernel@vger.kernel.org, Dexuan Cui , linux-crypto@vger.kernel.org, Eric Biggers , "David S. Miller" , Jonathan Corbet , linux-doc@vger.kernel.org Subject: Re: [PATCH] Documentation: crypto: add info about "fips=" boot option Message-ID: <20210330050222.GA28431@gondor.apana.org.au> References: <20210330040001.31524-1-rdunlap@infradead.org> <20210330043747.GA28166@gondor.apana.org.au> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.10.1 (2018-07-13) Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org On Mon, Mar 29, 2021 at 10:00:45PM -0700, Randy Dunlap wrote: > On 3/29/21 9:37 PM, Herbert Xu wrote: > > On Mon, Mar 29, 2021 at 09:00:01PM -0700, Randy Dunlap wrote: > >> > >> + If fips_enabled = 1, some crypto tests are skipped. > > > > I don't think any tests are skipped. It does however disable > > many algorithms by essentially failing them at the testing stage. > > That statement was based on crypto/testmgr.c (in 4 places): > > if (fips_enabled && template[i].fips_skip) > continue; By skipping the test, the algorithm effectively fails the self-test and therefore is disabled. Cheers, -- Email: Herbert Xu Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt