Re: F45 Change Proposal: Disable in Kernel Crypto Userspace API (Phase 1) (self-contained)

Ondrej Kozina via devel <[email protected]> Fri, 24 Jul 2026 14:04:36 +0200
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <[email protected]>
On 24/07/2026 12:19, Daniel P. Berrangé wrote:
> On Fri, Jul 24, 2026 at 11:56:22AM +0200, Ondrej Kozina via devel wrote:
>>
>> - No Adiantum in userspace crypto libraries currently supported by
>> libcryptsetup. The fallback via dm-crypt will again need CAP_SYS_ADMIN.
>> Affects LUKS2.
> 
> Is there anything blocking addition of these to openssl, or is it merely
> that no one has requested it historically ? (Perhaps naively) I would
> think that openssl ought to be supporting all of the cipher/mode.

I really can't say for sure. I'd only guess people did not care as there 
was an alternative via AF_ALG, at least in libcryptsetup use case.

But adding new things in libraries take time and a _lot_ of effort. You 
can read about 2+ years journey of Argon2 KDF in openssl[1][2], if you'd 
like :)

Of course, it will be better to have it in userspace crypto libs.

/shrug

O.

[1] https://github.com/openssl/openssl/pull/12255
[2] https://github.com/openssl/openssl/pull/12256

> 
> With regards,
> Daniel

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new