Re: [OS-BUILD PATCH] wireguard: disable in FIPS mode

2021-04-07 Thread Hangbin Liu (via Email Bridge)
From: Hangbin Liu on gitlab.com https://gitlab.com/cki-project/kernel-ark/-/merge_requests/994#note_546433292 @marcelo.leitner Sorry, I set the notification to only mentioned. I have updated the patch. Please help review. ___ kernel mailing list -- kerne

Re: [OS-BUILD PATCH] wireguard: disable in FIPS mode

2021-04-01 Thread Marcelo Ricardo Leitner (via Email Bridge)
From: Marcelo Ricardo Leitner on gitlab.com https://gitlab.com/cki-project/kernel-ark/-/merge_requests/994#note_543351708 Considering this will be visible to the user that tries to load the module, EPERM can be misleading. It can mean that a SELinux policy is blocking it (EPERM and EACCES are used

Re: [OS-BUILD PATCH] wireguard: disable in FIPS mode

2021-04-01 Thread Hangbin Liu (via Email Bridge)
From: Hangbin Liu on gitlab.com https://gitlab.com/cki-project/kernel-ark/-/merge_requests/994#note_543088211 @jbencrh @sdubroca @marcelo.leitner would you please help review? Thanks! ___ kernel mailing list -- kernel@lists.fedoraproject.org To unsubscri

[OS-BUILD PATCH] wireguard: disable in FIPS mode

2021-04-01 Thread Hangbin Liu (via Email Bridge)
From: Hangbin Liu wireguard: disable in FIPS mode Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1940794 Upstream: RHEL Only As the cryptos(BLAKE2S, Curve25519, CHACHA20POLY1305) in WireGuard are not FIPS certified, the WireGuard module should be disabled in FIPS mode. Signed-off-by: Ha