From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
To: herbert@gondor.apana.org.au, davem@davemloft.net,
johannes@sipsolutions.net, miriam.rachel.korenblit@intel.com
Cc: ilan.peer@intel.com, emmanuel.grumbach@intel.com,
linux-crypto@vger.kernel.org, linux-wireless@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v3 0/4] wifi: add opt-in FIPS exception for iwlwifi
Date: Fri, 9 Oct 2026 08:54:09 +0200 [thread overview]
Message-ID: <20261009065413.53403-1-jtornosm@redhat.com> (raw)
Commits 5241526dede9 ("wifi: mac80211: don't send keys
to driver when fips_enabled") and 0636800c8ee1 ("wifi:
iwlwifi: disable certain features for fips_enabled")
disabled WiFi functionality under FIPS mode because
Intel firmware autonomously sends some management
frames without FIPS-validated integrity protection.
While this is technically correct, it leaves
FIPS-required environments with no WiFi connectivity
at all, since WPA3-SAE mandates MFP and without
MFP_CAPABLE the client cannot even associate.
This series introduces an opt-in fips_exception=<bitmap>
kernel boot parameter that allows administrators who
understand the firmware limitation to explicitly choose
connectivity over strict compliance. No keys are
installed in firmware; mac80211 handles all data
encryption/decryption in software using FIPS-approved
algorithms. The default behavior remains exactly as the
original commits implemented.
This is a provisional v3 to show the current working
state and continue the conversation from [1]. Changes
and pending items are based on Johannes's very helpful
guidance.
With fips=1 fips_exception=1 on Intel AX211, this
series enables:
- MFP (802.11w) with software crypto in mac80211
- RX AMPDU aggregation
- Bidirectional data with no keys in firmware
Known limitation:
- No TX A-MPDU aggregation. Firmware sends ADDBA
unprotected, AP drops it (MFP). Host-driven ADDBA
from mac80211 can work at the protocol level but
TLC does not aggregate. Details in [1].
Pending for later versions:
- IGTK/BIGTK offload to firmware
- 6 GHz / EHT dependencies
- TX aggregation (if possible)
Test setup:
AP: WPA2-PSK ieee80211w=2, channel 52 80MHz HE
STA: Intel AX211, fips=1 fips_exception=1
RX: ~450 Mbps (iperf3)
TX: ~26 Mbps (iperf3, no A-MPDU)
[1] https://lore.kernel.org/all/20261009064326.43891-1-jtornosm@redhat.com/
v3: Address comments from Johannes:
- Drop PTK/GTK offload to firmware, software-only
crypto
- Drop A-MSDU size restoration
- Drop set_rekey_offload
Per patch:
- 1/4: same as v2 1/5 but fips_allows() renamed to
fips_allows_exception() with more suitable semantics
- 2/4: v2 2/5 (key gate), v2 3/5 (feature restore)
and v2 4/5 (SW_MGMT_TX) dropped, replaced by only
enabling MFP_CAPABLE
- 3/4: new, RX AMPDU and A-MSDU fixes for SW crypto
path
- 4/4: same as v2 5/5
v2: https://lore.kernel.org/all/20260930120829.383408-1-jtornosm@redhat.com/
Jose Ignacio Tornos Martinez (4):
crypto: fips: add fips_exception kernel boot parameter
and fips_allows_exception() helper
wifi: iwlwifi: enable MFP_CAPABLE in FIPS mode
wifi: iwlwifi: fix RX AMPDU and A-MSDU in FIPS mode
wifi: iwlwifi: reduce encryption error message to
debug level in FIPS mode
next reply other threads:[~2026-10-09 6:54 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 6:54 Jose Ignacio Tornos Martinez [this message]
2026-10-09 6:54 ` [PATCH v3 1/4] crypto: fips: add fips_exception kernel boot parameter and fips_allows_exception() helper Jose Ignacio Tornos Martinez
2026-10-09 6:54 ` [PATCH v3 2/4] wifi: iwlwifi: enable MFP_CAPABLE in FIPS mode Jose Ignacio Tornos Martinez
2026-10-09 6:54 ` [PATCH v3 3/4] wifi: iwlwifi: fix RX AMPDU and A-MSDU " Jose Ignacio Tornos Martinez
2026-10-09 6:54 ` [PATCH v3 4/4] wifi: iwlwifi: reduce encryption error message to debug level " Jose Ignacio Tornos Martinez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009065413.53403-1-jtornosm@redhat.com \
--to=jtornosm@redhat.com \
--cc=davem@davemloft.net \
--cc=emmanuel.grumbach@intel.com \
--cc=herbert@gondor.apana.org.au \
--cc=ilan.peer@intel.com \
--cc=johannes@sipsolutions.net \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=miriam.rachel.korenblit@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®