Re: [PATCH] libceph: Re-establish the FIPS keylength check in the Ceph code

Eric Biggers <[email protected]>
Newsgroups org.kernel.vger.ceph-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Fri, Aug 21, 2026 at 05:53:15PM +0000, Eric Biggers wrote:
> Do Ceph session keys shorter than 128 bits even actually occur in
> practice?  It seems that the Ceph authenticated modes support only
> AES-based cipher suites, where the minimum valid session key length is
> 128 bits.
> 
> I wonder if the client should just reject session_key_len < 16
> regardless of fips_enabled.

It looks like this is theoretically possible only when CEPH_AUTH_CEPHX
is being used but the session key uses CEPH_CRYPTO_NONE, which seems
insecure and contradictory, and likely not ever used by the server.  I
suspect the ceph client should just reject that combination outright
(and also session_key_len < 16 as defense-in-depth).  It is up to the
ceph folks who are the experts here, but if there are unnecessary
footguns like this, they should just be fixed for everyone.

- Eric
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.