Re: [PATCH] libceph: Re-establish the FIPS keylength check in the Ceph code

Eric Biggers <[email protected]>
Newsgroups org.kernel.vger.ceph-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Fri, Aug 21, 2026 at 04:43:22PM +0200, Thomas Huth wrote:
> When the Ceph code had been updated to use the libcrypto hmac_sha256
> functions instead of the "hmac(sha256)" crypto shash driver, we lost
> the FIPS key length check from  hmac_setkey() in crypto/hmac.c.

Well, except on s390 which already didn't do the FIPS key length check.

> @@ -720,6 +722,9 @@ static int setup_crypto(struct ceph_connection *con,
>  		return 0;  /* auth_none */
>  	}
>  
> +	if (fips_enabled && session_key_len < 112 / 8)
> +		return -EKEYREJECTED;
> +

I assume it's intentional that auth_none is still FIPS-allowed?  Kind of
ironic.

Do Ceph session keys shorter than 128 bits even actually occur in
practice?  It seems that the Ceph authenticated modes support only
AES-based cipher suites, where the minimum valid session key length is
128 bits.

I wonder if the client should just reject session_key_len < 16
regardless of fips_enabled.

- Eric
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.