From: Thomas Huth <thuth@redhat.com>
To: Joachim Vandersmissen <joachim@jvdsn.com>
Cc: "David S. Miller" <davem@davemloft.net>,
Maxime Coquelin <mcoquelin.stm32@gmail.com>,
Alexandre Torgue <alexandre.torgue@foss.st.com>,
linux-crypto@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org,
Herbert Xu <herbert@gondor.apana.org.au>
Subject: Re: [PATCH] crypto: testmgr - block Crypto API xxhash64 in FIPS mode
Date: Thu, 10 Sep 2026 10:57:32 +0200 [thread overview]
Message-ID: <48f12b65-428d-4809-9735-18876b09e759@redhat.com> (raw)
In-Reply-To: <83d09aa1-729a-47a2-a8e9-381c74e92f42@jvdsn.com>
On 10/09/2026 05.24, Joachim Vandersmissen wrote:
> Hi Thomas,
>
> On 9/9/26 9:36 AM, Thomas Huth wrote:
>> On 15/03/2026 01.43, Joachim Vandersmissen wrote:
>>> Hi Herbert,
>>>
>>> I don't think this one can be applied yet since dm-integrity still uses
>>> xxhash64 through the crypto API. This would break fips=1 systems that use
>>> it.
>>
>> Out of curiosity: Wouldn't such a system be FIPS-incompliant anyway? If
>> xxhash64 isn't FIPS-compliant, nobody should use it for dm-integrity
>> there, right? So I doubt that there are any systems out there that use
>> fips=1 and use xxhash64 at the same time?
>
> There is a risk that users may not know that xxhash64 is not FIPS compliant
> and would still use it. Especially considering it was marked as
> "fips_allowed = 1" for a while.
So isn't that a very bad situation? They think they are FIPS compliant, but
actually they are not since they use an unapproved algorithm by accident.
Maybe it would be better to include this patch so that they are aware of the
mistake? If there is really somebody running into this issue, they could
boot once with fips=0, fix their system, reboot again with fips=1 and
finally be really compliant. Sounds like the better solution to me. WDYT?
Thomas
next prev parent reply other threads:[~2026-09-10 8:57 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-03 6:05 [PATCH] crypto: testmgr - block Crypto API xxhash64 in FIPS mode Joachim Vandersmissen
2026-03-03 15:09 ` Christoph Hellwig
2026-03-03 19:31 ` Eric Biggers
2026-03-04 9:55 ` Milan Broz
2026-03-04 13:09 ` Christoph Hellwig
2026-03-05 7:19 ` Joachim Vandersmissen
2026-03-14 5:11 ` Herbert Xu
2026-03-15 0:43 ` Joachim Vandersmissen
2026-03-15 4:32 ` Herbert Xu
2026-09-09 14:36 ` Thomas Huth
2026-09-10 3:24 ` Joachim Vandersmissen
2026-09-10 8:57 ` Thomas Huth [this message]
2026-09-10 14:14 ` Eric Biggers
2026-09-11 2:53 ` Joachim Vandersmissen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48f12b65-428d-4809-9735-18876b09e759@redhat.com \
--to=thuth@redhat.com \
--cc=alexandre.torgue@foss.st.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=joachim@jvdsn.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mcoquelin.stm32@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox