mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Stephan Mueller <smueller@chronox.de>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org,
	aquini@redhat.com, jeremy.wayne.powell@gmail.com,
	clemens@ladisch.de, pwalten@au1.ibm.com, joe@perches.com
Subject: Re: [PATCH v7 0/6] SP800-90A Deterministic Random Bit Generator
Date: Mon, 26 May 2014 07:42:57 +0200	[thread overview]
Message-ID: <1449817.RiX7azh5Ri@myon.chronox.de> (raw)
In-Reply-To: <20140523211459.GA21019@gondor.apana.org.au>

Am Samstag, 24. Mai 2014, 05:14:59 schrieb Herbert Xu:

Hi Herbert,

> Stephan Mueller <smueller@chronox.de> wrote:
> > Hi,
> > 
> > the following set of patches implements the deterministic random bit
> > generator (DRBG) specified by SP800-90A.
> > 
> > The DRBG implementation offers the following:
> >        * All three DRBG types are implemented with a derivation function.
> >        * All DRBG types are available with and without prediction
> >        resistance.
> >        * All SHA types of SHA-1, SHA-256, SHA-384, SHA-512 are available
> >        
> >          for the HMAC and Hash DRBGs.
> >        
> >        * All AES types of AES-128, AES-192 and AES-256 are available for
> >        the
> >        
> >          CTR DRBG.
> >        
> >        * A self test is implemented with drbg_healthcheck().
> >        * The FIPS 140-2 continuous self test is implemented.
> >        * Additional cipher primitives, such as Serpent or Twofish, can be
> >        
> >          added to the DRBG without changing the implementation. The only
> >          change necessary is to the DRBG definition given in the cores[]
> >          array.
> 
> Where is the code that actually uses this?

There are several answers to this.

First: as required by NIST SP800-131A, the ANSI X9.31 DRNG is considered to be 
sunset by the end of 2015. The FIPS 140-2 validation part of NIST requires 
that ANSI X9.31 DRNGs are not allowed for new validations since the start of 
this year and prohibited for revalidations starting next year. The replacement 
of ANSI X9.31 is SP800-90A.

The Linux kernel currently implements one DRNG in ansi_cprng.c. This DRNG is 
an ANSI X9.31 DRNG. This means, the offered SP800-90A implementation can be 
considered a replacement of ansi_cprng.c.

A second aspect is the implementation of the stdrng. Currently, the offered 
patch does not include the stdrng selection. I am currently working on the 
completion of the addition of the stdrng selection to the offered patch. My 
idea is the following: currently, all DRBG types are registered with their own 
cra_name. However, there shall be one particular DRBG registered twice. When 
registering the instance again, the cra_name shall be "stdrng". In addition, 
if the kernel command line contains fips=1, the cra_priority of that stdrng 
should be set to 300. That implies that when the kernel resolves the stdrng, 
it resolves to get_random_bytes in normal mode, but to the stdrng DRBG in FIPS 
mode.

Here some code snippet from my patch I am working on:

if (fips_stdrng) {
                memcpy(alg->cra_name, "stdrng", 6);

...

if (fips_stdrng)
                alg->cra_priority = 300;
        else
                alg->cra_priority = 100;

Ciao
Stephan
-- 
| Cui bono? |

  reply	other threads:[~2014-05-26  5:43 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-05-21  4:18 Stephan Mueller
2014-05-21  4:18 ` [PATCH v7 1/6] " Stephan Mueller
2014-05-21 20:17   ` Stephan Mueller
2014-05-23 21:10   ` Herbert Xu
2014-05-26  5:44     ` Stephan Mueller
2014-05-21  4:19 ` [PATCH v7 2/6] header file for DRBG Stephan Mueller
2014-05-21  4:20 ` [PATCH v7 3/6] DRBG kernel configuration options Stephan Mueller
2014-05-21  4:21 ` [PATCH v7 4/6] compile the DRBG code Stephan Mueller
2014-05-21  4:21 ` [PATCH v7 5/6] DRBG testmgr test vectors Stephan Mueller
2014-05-21  4:22 ` [PATCH v7 6/6] Add DRBG test code to testmgr Stephan Mueller
2014-05-23 21:14 ` [PATCH v7 0/6] SP800-90A Deterministic Random Bit Generator Herbert Xu
2014-05-26  5:42   ` Stephan Mueller [this message]
2014-05-30  9:05     ` Herbert Xu
2014-05-30 10:08       ` Stephan Mueller
2014-05-30 10:52         ` Herbert Xu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1449817.RiX7azh5Ri@myon.chronox.de \
    --to=smueller@chronox.de \
    --cc=aquini@redhat.com \
    --cc=clemens@ladisch.de \
    --cc=herbert@gondor.apana.org.au \
    --cc=jeremy.wayne.powell@gmail.com \
    --cc=joe@perches.com \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pwalten@au1.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®