From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:52587) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cDrIW-0008AH-O7 for qemu-devel@nongnu.org; Mon, 05 Dec 2016 06:19:08 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cDrIS-00057F-42 for qemu-devel@nongnu.org; Mon, 05 Dec 2016 06:19:04 -0500 Received: from mx1.redhat.com ([209.132.183.28]:56428) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cDrIR-000572-Tt for qemu-devel@nongnu.org; Mon, 05 Dec 2016 06:19:00 -0500 Date: Mon, 5 Dec 2016 11:18:53 +0000 From: "Daniel P. Berrange" Message-ID: <20161205111853.GD2498@redhat.com> Reply-To: "Daniel P. Berrange" References: <1480928380-161760-1-git-send-email-longpeng2@huawei.com> <1480928380-161760-2-git-send-email-longpeng2@huawei.com> <20161205091842.GA2498@redhat.com> <58454B69.4040402@huawei.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <58454B69.4040402@huawei.com> Subject: Re: [Qemu-devel] [PATCH for-2.9 1/3] crypto: add standard des support List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "Longpeng (Mike)" Cc: eblake@redhat.com, armbru@redhat.com, arei.gonglei@huawei.com, qemu-devel@nongnu.org, wu.wubin@huawei.com, jianjay.zhou@huawei.com On Mon, Dec 05, 2016 at 07:11:37PM +0800, Longpeng (Mike) wrote: > Hi Daniel, > > On 2016/12/5 17:18, Daniel P. Berrange wrote: > > > On Mon, Dec 05, 2016 at 04:59:38PM +0800, Longpeng(Mike) wrote: > ...... > >> diff --git a/qapi/crypto.json b/qapi/crypto.json > >> index 5c9d7d4..d403ab9 100644 > >> --- a/qapi/crypto.json > >> +++ b/qapi/crypto.json > >> @@ -75,7 +75,7 @@ > >> { 'enum': 'QCryptoCipherAlgorithm', > >> 'prefix': 'QCRYPTO_CIPHER_ALG', > >> 'data': ['aes-128', 'aes-192', 'aes-256', > >> - 'des-rfb', > >> + 'des-rfb', 'des', > > > > Can we call this '3des' to make it clear that this is Triple-DES and not > > the single-DES (which des-rfb is) > > > > As the comment in qapi/crypto.json said: > @des-rfb: RFB specific variant of single DES. > > This patch just add the standard single-DES support, not the triple-DES, so I > think maybe "des" is suitable. Oh I missed that - QEMU should not support single-DES at all for cryptodev IMHO. Single DES has been cryptographically broken/useless for *decades* - way back in 1999, the EFF built a machine that could brute force single-DES in a mere 56 hours. Triple-DES is the bare minimum that's acceptable and even that should only be for legacy usage which can't use a more modern cipher like AES Regards, Daniel -- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://entangle-photo.org -o- http://search.cpan.org/~danberr/ :|