• Linus Torvalds's avatar
    Merge tag 'certs-20220621' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs · 0273fd42
    Linus Torvalds authored
    Pull signature checking selftest from David Howells:
     "The signature checking code, as used by module signing, kexec, etc.,
      is non-FIPS compliant as there is no selftest.
    
      For a kernel to be FIPS-compliant, signature checking would have to be
      tested before being used, and the box would need to panic if it's not
      available (probably reasonable as simply disabling signature checking
      would prevent you from loading any driver modules).
    
      Deal with this by adding a minimal test.
    
      This is split into two patches: the first moves load_certificate_list()
      to the same place as the X.509 code to make it more accessible
      internally; the second adds a selftest"
    
    * tag 'certs-20220621' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs:
      certs: Add FIPS selftests
      certs: Move load_certificate_list() to be with the asymmetric keys code
    0273fd42
Makefile 3.28 KB