RE: [EXT] [PATCH v8 3/6] KEYS: trusted: Introduce NXP DCP-backed trusted keys

2024-04-10 Thread Kshitiz Varshney
ngutronix Kernel Team ; > Tejun Heo ; linux-integr...@vger.kernel.org; Shawn Guo > ; Varun Sethi > Subject: Re: [EXT] [PATCH v8 3/6] KEYS: trusted: Introduce NXP DCP-backed > trusted keys > > Caution: This is an external email. Please take care when clicking links or > ope

RE: [EXT] [PATCH v8 3/6] KEYS: trusted: Introduce NXP DCP-backed trusted keys

2024-04-09 Thread Kshitiz Varshney
Hi David, > -Original Message- > From: David Gstir > Sent: Wednesday, April 3, 2024 12:51 PM > To: Mimi Zohar ; James Bottomley > ; Jarkko Sakkinen ; Herbert Xu > ; David S. Miller > Cc: David Gstir ; Shawn Guo ; > Jonathan Corbet ; Sascha Hauer > ; Pengutronix Kernel Team > ; Fabio

Re: [EXT] [PATCH v8 3/6] KEYS: trusted: Introduce NXP DCP-backed trusted keys

2024-04-09 Thread Ahmad Fatoum
Hello Kshitiz, On 09.04.24 12:54, Kshitiz Varshney wrote: > Hi David, >> + b->fmt_version = DCP_BLOB_VERSION; >> + get_random_bytes(b->nonce, AES_KEYSIZE_128); >> + get_random_bytes(b->blob_key, AES_KEYSIZE_128); > > We can use HWRNG instead of using kernel RNG. Please refer >