Re: F45 Change Proposal: Disable in Kernel Crypto Userspace API (Phase 1) (self-contained)
Ondrej Kozina via devel <[email protected]> Fri, 24 Jul 2026 15:12:01 +0200
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <[email protected]> |
On 24/07/2026 13:07, Barry Scott wrote: > > >> On 24 Jul 2026, at 11:15, Peter Robinson <[email protected]> wrote: >> >>> - there's no xts mode implemented for camellia, serpent and twofish >>> ciphers in openssl (I mention only the most used AES alternatives). So >>> the cryptsetup (in Fedora) will loose userspace access to those ciphers >>> without CAP_SYS_ADMIN. Affects LUKS2. >> >> Can you provide details of where they are used in Fedora? I believe >> these would only be used if a user when out of their way to use those, >> generally via a manual install process. > > I'm one of the people that has done manual setup with a cypher that is > affected. > > On a Rpi4 I have a luks2 vault that I setup with advice from the > *internet* that advised to > use these setting as the Rpi would strugle with the defaults. > > Cipher: aes-xts-plain64 > PBKDF: argon2id > > Clearly I will have to migrate to a supported cypher before upgrading to > f45. For the ciphers mentioned above (camellia, serpent, twofish or adiantum): To unlock the device and establish dm-crypt mapping (aka "cryptsetup open") you need CAP_SYS_ADMIN (or root access) anyway. For this, you should not be affected. The cipher implementations remain in kernel. You will only loose the root-less access to LUKS containers because there is no alternative implementation in userspace crypto libraries for those ciphers. No adiantum at all, xts modes missing for the rest in openssl. O. -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new