From: Roger Luethi <rl@hellgate.ch>
To: Linus Torvalds <torvalds@transmeta.com>
Cc: Dax Kelson <dax@gurulabs.com>,
Alan Cox <alan@lxorguk.ukuu.org.uk>,
"Kendrick M. Smith" <kmsmith@umich.edu>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"nfs@lists.sourceforge.net" <nfs@lists.sourceforge.net>,
beepy@netapp.com, trond.myklebust@fys.uio.no
Subject: Re: Will NFSv4 be accepted?
Date: Thu, 15 Aug 2002 21:52:31 +0200 [thread overview]
Message-ID: <20020815195231.GA18239@k3.hellgate.ch> (raw)
In-Reply-To: <Pine.LNX.4.44.0208151027510.3130-100000@home.transmeta.com>
On Thu, 15 Aug 2002 10:35:40 -0700, Linus Torvalds wrote:
>
> On Wed, 14 Aug 2002, Dax Kelson wrote:
> >
> > Q for Linus: What's the prospect of adding crypto to the kernel?
>
> For a good enough excuse, and with a good enough argument that it's not
> likely to be a big export problem, I don't think it's impossible any more.
>
> However, the "good enough excuse" has to be better than "some technically
> excellent, but not very widespread" thing.
While I'm all for adding crypto to the standard kernel, I contend the
crucial part is not strong crypto, but the API. With a stock kernel that
merely offered rot13 type algorithms and a simple way to add more, we could
sidestep the export issue [1] if necessary and still get important
benefits.
There have been some efforts to find a common platform (e.g. between the
freeswan and the cryptoapi folks recently), but the driving force that
brought us LSM is sorely missing with crypto, although the issue seems less
complex.
I won't comment on the technical excellence of the currently available
solutions, but VPNs and disk encryption (especially for laptop owners) are
quite likely to see (even more) widespread use in the near future. With
Reiser4 it seems there is soon going to be another contender in local
filesystems besides the loopback based ones. RedHat, Mandrake, and SuSE are
already selling products using kernel space encryption (i.e. VPNs and/or
encrypted filesystems).
IMHO the case for crypto in the kernel has already been made. The questions
are rather: what would a kernel crypto facility look like if it was to be
useful for all those projects out there, and who could pull an LSM on this
one?
Roger
[1] Assuming that the times when even crypto _hooks_ were likely a felony
are gone for good (for many countries anyway). IANAL, obviously.
next prev parent reply other threads:[~2002-08-15 19:49 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-08-13 23:01 patch 14/38: CLIENT: add ->setup_read() nfs_rpc_op for async read, part 1 Kendrick M. Smith
2002-08-14 20:49 ` Will NFSv4 be accepted? Dax Kelson
2002-08-14 22:17 ` Trond Myklebust
2002-08-14 22:34 ` [NFS] " Brian Pawlowski
2002-08-14 23:21 ` Alexander Viro
2002-08-15 1:10 ` Alan Cox
2002-08-15 6:18 ` marius aamodt eriksen
2002-08-15 11:08 ` Alan Cox
2002-08-15 6:23 ` marius aamodt eriksen
2002-08-15 14:19 ` Trond Myklebust
2002-08-15 1:09 ` Alan Cox
2002-08-15 1:27 ` Dax Kelson
2002-08-15 1:35 ` Alan Cox
2002-08-15 1:51 ` Dax Kelson
2002-08-15 4:07 ` J. Bruce Fields
2002-08-15 17:35 ` Linus Torvalds
2002-08-15 18:20 ` Dax Kelson
2002-08-15 19:52 ` Roger Luethi [this message]
2002-08-15 23:07 ` Trond Myklebust
2002-08-16 14:54 ` Oliver Xymoron
2002-08-16 19:44 ` Linus Torvalds
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20020815195231.GA18239@k3.hellgate.ch \
--to=rl@hellgate.ch \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=beepy@netapp.com \
--cc=dax@gurulabs.com \
--cc=kmsmith@umich.edu \
--cc=linux-kernel@vger.kernel.org \
--cc=nfs@lists.sourceforge.net \
--cc=torvalds@transmeta.com \
--cc=trond.myklebust@fys.uio.no \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox