Browse Source
This patch cleans up the default list of kernel modules in the 01fips dracut module. All the algorithms that are tested in tcrypt are listed by their algorithm name so that all the generic implementations and drivers are picked up automatically based on the module alias. This drops several unneeded modules and even a bogus one (rot13 -- this one was obviously copy-pasted from tcrypt.c where it was listed as an easter egg :). The patch adds also some algorithms that weren't included in the original set. It turns out in FIPS mode we only need those algorithms that are marked as FIPS-allowed in testmgr.c (failure to find a non-FIPS algorithm is ignored). The non-FIPS algorithms are further removed in a subsequent patch.master
data:image/s3,"s3://crabby-images/a8656/a86569103aa29db44a783f016e2b8703656c4d27" alt="omosnace@redhat.com"
data:image/s3,"s3://crabby-images/a8656/a86569103aa29db44a783f016e2b8703656c4d27" alt="Harald Hoyer"
1 changed files with 28 additions and 7 deletions
Loading…
Reference in new issue