crypto: xts - restrict key lengths to approved values in FIPS mode
authorNicolai Stange <nstange@suse.de>
Thu, 29 Dec 2022 21:17:05 +0000 (22:17 +0100)
committerHerbert Xu <herbert@gondor.apana.org.au>
Fri, 6 Jan 2023 09:15:46 +0000 (17:15 +0800)
commit1c4428b295884316eaff16be9c1d85f7c2361696
tree93daad08b6d207cffea11813ce6c96e641d92384
parent39a76cf1f5cecec2256ab2d20cf714573c5d994c
crypto: xts - restrict key lengths to approved values in FIPS mode

According to FIPS 140-3 IG C.I., only (total) key lengths of either
256 bits or 512 bits are allowed with xts(aes). Make xts_verify_key() to
reject anything else in FIPS mode.

As xts(aes) is the only approved xts() template instantiation in FIPS mode,
the new restriction implemented in xts_verify_key() effectively only
applies to this particular construction.

Signed-off-by: Nicolai Stange <nstange@suse.de>
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
include/crypto/xts.h