* [RFC] crypto: exynos - Icrease the priority of the driver [not found] <CGME20171205124216eucas1p17f46fc23ea35f7f2fcacc49d88e40a15@eucas1p1.samsung.com> @ 2017-12-05 12:42 ` Łukasz Stelmach 2017-12-05 13:48 ` Stephan Mueller 0 siblings, 1 reply; 2+ messages in thread From: Łukasz Stelmach @ 2017-12-05 12:42 UTC (permalink / raw) To: Krzysztof Kozlowski, robh+dt, Stephan Mueller, Herbert Xu, David S. Miller, Kukjin Kim, linux-crypto, linux-samsung-soc, linux-kernel Cc: Łukasz Stelmach, m.szyprowski, b.zolnierkie exynos-rng is one of many implementations of stdrng. With priority as low as 100 it isn't selected, if software implementations (DRBG) are available. Signed-off-by: Łukasz Stelmach <l.stelmach@samsung.com> --- If not 1000, what is the best value, what is the policy? drivers/crypto/exynos-rng.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/crypto/exynos-rng.c b/drivers/crypto/exynos-rng.c index 0bf07a655813..3c514eaae9dc 100644 --- a/drivers/crypto/exynos-rng.c +++ b/drivers/crypto/exynos-rng.c @@ -259,7 +259,7 @@ static struct rng_alg exynos_rng_alg = { .base = { .cra_name = "stdrng", .cra_driver_name = "exynos_rng", - .cra_priority = 100, + .cra_priority = 1000, .cra_ctxsize = sizeof(struct exynos_rng_ctx), .cra_module = THIS_MODULE, .cra_init = exynos_rng_kcapi_init, -- 2.11.0 ^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [RFC] crypto: exynos - Icrease the priority of the driver 2017-12-05 12:42 ` [RFC] crypto: exynos - Icrease the priority of the driver Łukasz Stelmach @ 2017-12-05 13:48 ` Stephan Mueller 0 siblings, 0 replies; 2+ messages in thread From: Stephan Mueller @ 2017-12-05 13:48 UTC (permalink / raw) To: Łukasz Stelmach Cc: Krzysztof Kozlowski, robh+dt, Herbert Xu, David S. Miller, Kukjin Kim, linux-crypto, linux-samsung-soc, linux-kernel, m.szyprowski, b.zolnierkie Am Dienstag, 5. Dezember 2017, 13:42:14 CET schrieb Łukasz Stelmach: Hi Łukasz, > exynos-rng is one of many implementations of stdrng. With priority as > low as 100 it isn't selected, if software implementations (DRBG) are > available. What about using 300? The reason is the following: in the normal case, the software PRNGs have 100 (X9.31) and 200 (SP800-90A DRBG). Thus, in normal case, the hardware takes precedence. In FIPS mode, the DRBG prio is increased by 200. As in FIPS mode you must have a DRBG and assuming that the hardware does not implement a DRBG, the software DRBG should be used as otherwise you have a FIPS-problem. Ciao Stephan ^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-12-05 13:48 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <CGME20171205124216eucas1p17f46fc23ea35f7f2fcacc49d88e40a15@eucas1p1.samsung.com>
2017-12-05 12:42 ` [RFC] crypto: exynos - Icrease the priority of the driver Łukasz Stelmach
2017-12-05 13:48 ` Stephan Mueller
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®