All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tapas Sarangi <TSarangi@trustwave.com>
To: "linux-crypto@vger.kernel.org" <linux-crypto@vger.kernel.org>
Subject: RSA key size not allowed in FIPS
Date: Tue, 9 Aug 2016 14:10:33 +0000	[thread overview]
Message-ID: <D3CF4E8C.2883%tsarangi@trustwave.com> (raw)

Hello,

I am using vanilla kernel-4.7 source. It crashes with the following when
booted with ³fips=1 boot=/dev/sda1² option at the kernel command line
argument.

[    0.642411] RSA: key size not allowed in FIPS mode
[    0.643099] Problem loading in-kernel X.509 certificate (-22)
[    0.800524] BUG: unable to handle kernel NULL pointer dereference at
0000000000000068
[    0.803075] IP: [<ffffffff811e1ad7>] kernfs_find_ns+0x17/0xf0
[    0.804111] PGD 0
[    0.804111] Oops: 0000 [#1] SMP
[    0.804111] Modules linked in:
[    0.804111] CPU: 0 PID: 6 Comm: kworker/u2:0 Tainted: G        W
4.7.0-1.tos2_5 #1
[    0.804111] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
1.8.2-20150714_191134- 04/01/2014
[    0.804111] Workqueue: events_unbound async_run_entry_fn
[    0.804111] task: ffff88003e214100 ti: ffff88003e264000 task.ti:
ffff88003e264000
[    0.804111] RIP: 0010:[<ffffffff811e1ad7>]  [<ffffffff811e1ad7>]
kernfs_find_ns+0x17/0xf0
[    0.804111] RSP: 0018:ffff88003e267868  EFLAGS: 00010282
[    0.804111] RAX: ffff88003e214100 RBX: 0000000000000000 RCX:
ffff88003e264008
[    0.804111] RDX: 0000000000000000 RSI: ffffffff8166bb80 RDI:
0000000000000000
[    0.804111] RBP: ffff88003e267898 R08: 0000000000000000 R09:
ffffffff8166bb80
[    0.804111] R10: 00000000000c6000 R11: 0000000000000001 R12:
ffffffff8166bb80
[    0.804111] R13: 0000000000000000 R14: ffffffff8173048a R15:
ffff88003b17b1a0
[    0.804111] FS:  0000000000000000(0000) GS:ffff88003fc00000(0000)
knlGS:0000000000000000
[    0.804111] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[    0.804111] CR2: 0000000000000068 CR3: 0000000001806000 CR4:
00000000000406f0
[    0.804111] Stack:
[    0.804111]  ffff88003e267898 0000000000000000 ffff880000000001
0000000000000000
[    0.804111]  ffffffff8166bb80 0000000000000000 ffff88003e2678c8
ffffffff811e1e77
[    0.804111]  0000000000000096 ffffffff81873d40 ffff88003b152828
0000000000000005
[    0.804111] Call Trace:
[    0.804111]  [<ffffffff811e1e77>] kernfs_find_and_get_ns+0x37/0x60
[    0.804111]  [<ffffffff811e5c58>] sysfs_unmerge_group+0x18/0x60
[    0.804111]  [<ffffffff8139c187>] dpm_sysfs_remove+0x27/0x60



Thanks for any suggestion.
-Tapas
Ps : I could not send any attachment, is it possible to send attachment to
this mailing list ?




________________________________

This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.

             reply	other threads:[~2016-08-09 14:25 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-08-09 14:10 Tapas Sarangi [this message]
2016-08-09 14:29 ` RSA key size not allowed in FIPS Stephan Mueller
2016-08-09 14:39   ` Tapas Sarangi
2016-08-09 14:54     ` Tapas Sarangi
2016-08-09 14:55     ` Stephan Mueller
2016-08-09 15:00       ` Tapas Sarangi
2016-08-09 16:07         ` Tapas Sarangi
2016-08-09 16:08           ` Stephan Mueller
2016-08-16  9:33       ` Stephan Mueller
2016-08-09 14:36 ` Gary R Hook

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=D3CF4E8C.2883%tsarangi@trustwave.com \
    --to=tsarangi@trustwave.com \
    --cc=linux-crypto@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.