Received: by 2002:a05:6358:a55:b0:ec:fcf4:3ecf with SMTP id 21csp5137451rwb; Tue, 17 Jan 2023 09:36:18 -0800 (PST) X-Google-Smtp-Source: AMrXdXvGLgJljyVqJgpKzwQZf0yoQmkHPuzJCVjsZEyXVmOXKkfyUMw09pq2aWKjH1yNCUH/mJKh X-Received: by 2002:a17:90a:7105:b0:229:2dcc:7562 with SMTP id h5-20020a17090a710500b002292dcc7562mr4119515pjk.33.1673976978702; Tue, 17 Jan 2023 09:36:18 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1673976978; cv=none; d=google.com; s=arc-20160816; b=waCAQlvH0lIJJ/3yBvJVk6ZFBP5Cb0A2TIC4eNHVt8M3nmgCvPYoqzx/Fys8SdAeM7 swWgK178lAHgiSQdwOTEevowjUJ8zkOAOCfnbdPN8zFhPt8c+JLQBxRuGcaILtHyafAz NjqRslQbCgJrt6qCyJf2QPPmWg1OxWpMgkE3d1ViFn2kEiL3vTJMsoOEwcYKR5GfM7NL +4NVgcyAipLsoajfXCMyfhUWXDMvoY0HpLmXWzbvqjQiy/g0BW/C5mZuKRW934W9eHf6 ZK4StQLpZZ1ixu58mD4O7GKcjX6XoXs+vIk2Ean3XA067uE8tOwf5xwT9mKKrI5ZwInP pP+g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=1PRuX+JN7wqNln+FW4J1BUr8fMYCnc6M3GNZOEvdC2c=; b=Q9Cmg2b1TFALK5yudU7SnApp2Hmb4q8CEygwKZgD2z2fuSHYpHUeub4Wqy+80tkIaR jnYEpFitPLMYKqA+SG3SBLg2IVjZwu4aPxHwQCWkbb4vgVXZvXP2bgwJ5lFCBJFOCwg1 DU2RYg3009fD1AuGWPcWxUu6X6wIvDPkkJ+lIElyd1Yv0RgvY4Xl9LOhOZYr9OzHl391 ss0aWxZWSpo2at64G8xmK/8Vm7u7Y/YhSHL2fwpN4Hzcvk1x3tYgx1aG3JiNaQqNni2W m8MfsL7zQdVGiLN8bsggg8ZbDwdadG3/OCV9XeMnHsgrzBUDwMp/JUDI1r7CdMKFnB/Q +nKw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b="bnLXJs/C"; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id 134-20020a63028c000000b004cd418b1f06si6827972pgc.206.2023.01.17.09.35.58; Tue, 17 Jan 2023 09:36:18 -0800 (PST) Received-SPF: pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b="bnLXJs/C"; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232721AbjAQRXX (ORCPT + 99 others); Tue, 17 Jan 2023 12:23:23 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47368 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233033AbjAQRWc (ORCPT ); Tue, 17 Jan 2023 12:22:32 -0500 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 145B64B77D for ; Tue, 17 Jan 2023 09:20:38 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1673976037; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1PRuX+JN7wqNln+FW4J1BUr8fMYCnc6M3GNZOEvdC2c=; b=bnLXJs/CS30vUyvdjLw/E+CIA4UFLaSHSY9KJ8jtcLjFb8ct8AMcDe+KmGpasElkomc1GE jtx99DasnJ425X/TW8bAeOiZVC3Z1ZMlvJHewFayfdvlgOHzPmmxaWzvxn7Ab3bxBNXUU6 L9UtcwBN4qrMDkzIFSZg/F252hCEMgY= Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-618-zoROmHHFNWi7Yx2HUGpmQQ-1; Tue, 17 Jan 2023 12:20:32 -0500 X-MC-Unique: zoROmHHFNWi7Yx2HUGpmQQ-1 Received: from smtp.corp.redhat.com (int-mx07.intmail.prod.int.rdu2.redhat.com [10.11.54.7]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 3A44619705C0; Tue, 17 Jan 2023 17:20:32 +0000 (UTC) Received: from rules.brq.redhat.com (ovpn-208-27.brq.redhat.com [10.40.208.27]) by smtp.corp.redhat.com (Postfix) with ESMTP id F3B5C140EBF5; Tue, 17 Jan 2023 17:20:29 +0000 (UTC) From: Vladis Dronov To: Herbert Xu , "David S . Miller" Cc: Stephan Mueller , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, Vladis Dronov Subject: [PATCH] crypto: testmgr - disallow certain DRBG hash functions in FIPS mode Date: Tue, 17 Jan 2023 18:20:06 +0100 Message-Id: <20230117172006.8912-1-vdronov@redhat.com> MIME-Version: 1.0 Content-type: text/plain Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 3.1 on 10.11.54.7 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2,SPF_HELO_NONE,SPF_NONE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org According to FIPS 140-3 IG, section D.R "Hash Functions Acceptable for Use in the SP 800-90A DRBGs", modules certified after May 16th, 2023 must not support the use of: SHA-224, SHA-384, SHA512-224, SHA512-256, SHA3-224, SHA3-384. Disallow HMAC and HASH DRBGs using SHA-384 in FIPS mode. Signed-off-by: Vladis Dronov --- Some details: The following DRBG algos are defined in testmgr.c as of now: drbg_{no,}pr_ctr_aes128 drbg_{no,}pr_ctr_aes192 drbg_{no,}pr_ctr_aes256 drbg_{no,}pr_hmac_sha1 drbg_{no,}pr_hmac_sha256 drbg_{no,}pr_hmac_sha384 (disallow) drbg_{no,}pr_hmac_sha512 drbg_{no,}pr_sha1 drbg_{no,}pr_sha256 drbg_{no,}pr_sha384 (disallow) drbg_{no,}pr_sha512 Marked DRBGs should be disallowed in FIPS mode according to the requirements above. --- crypto/testmgr.c | 4 ---- 1 file changed, 4 deletions(-) diff --git a/crypto/testmgr.c b/crypto/testmgr.c index 4476ac97baa5..fbb53d961ea9 100644 --- a/crypto/testmgr.c +++ b/crypto/testmgr.c @@ -4782,7 +4782,6 @@ static const struct alg_test_desc alg_test_descs[] = { }, { /* covered by drbg_nopr_hmac_sha256 test */ .alg = "drbg_nopr_hmac_sha384", - .fips_allowed = 1, .test = alg_test_null, }, { .alg = "drbg_nopr_hmac_sha512", @@ -4805,7 +4804,6 @@ static const struct alg_test_desc alg_test_descs[] = { }, { /* covered by drbg_nopr_sha256 test */ .alg = "drbg_nopr_sha384", - .fips_allowed = 1, .test = alg_test_null, }, { .alg = "drbg_nopr_sha512", @@ -4841,7 +4839,6 @@ static const struct alg_test_desc alg_test_descs[] = { }, { /* covered by drbg_pr_hmac_sha256 test */ .alg = "drbg_pr_hmac_sha384", - .fips_allowed = 1, .test = alg_test_null, }, { .alg = "drbg_pr_hmac_sha512", @@ -4861,7 +4858,6 @@ static const struct alg_test_desc alg_test_descs[] = { }, { /* covered by drbg_pr_sha256 test */ .alg = "drbg_pr_sha384", - .fips_allowed = 1, .test = alg_test_null, }, { .alg = "drbg_pr_sha512", -- 2.39.0