mirror of
https://github.com/torvalds/linux
synced 2026-07-21 17:50:43 +09:00
Since the use of "pcbc(des)" in rxkad_decrypt_ticket() is the only remaining user of the crypto API "pcbc" template, just implement DES-PCBC by locally implementing PCBC mode on top of the DES library. Note that only the decryption direction is needed. This will allow support for the obsolete PCBC mode to be removed from the crypto API. Acked-by: David Howells <dhowells@redhat.com> Signed-off-by: Eric Biggers <ebiggers@kernel.org> Tested-by: Marc Dionne <marc.dionne@auristor.com> Link: https://patch.msgid.link/20260522050740.84561-4-ebiggers@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org>
104 lines
2.6 KiB
Plaintext
104 lines
2.6 KiB
Plaintext
# SPDX-License-Identifier: GPL-2.0-only
|
|
#
|
|
# RxRPC session sockets
|
|
#
|
|
|
|
config AF_RXRPC
|
|
tristate "RxRPC session sockets"
|
|
depends on INET
|
|
select CRYPTO
|
|
select CRYPTO_LIB_DES if RXKAD
|
|
select KEYS
|
|
select NET_UDP_TUNNEL
|
|
help
|
|
Say Y or M here to include support for RxRPC session sockets (just
|
|
the transport part, not the presentation part: (un)marshalling is
|
|
left to the application).
|
|
|
|
These are used for AFS kernel filesystem and userspace utilities.
|
|
|
|
This module at the moment only supports client operations and is
|
|
currently incomplete.
|
|
|
|
See Documentation/networking/rxrpc.rst.
|
|
|
|
if AF_RXRPC
|
|
|
|
config AF_RXRPC_IPV6
|
|
bool "IPv6 support for RxRPC"
|
|
depends on IPV6
|
|
help
|
|
Say Y here to allow AF_RXRPC to use IPV6 UDP as well as IPV4 UDP as
|
|
its network transport.
|
|
|
|
config AF_RXRPC_INJECT_LOSS
|
|
bool "Inject packet loss into RxRPC packet stream"
|
|
help
|
|
Say Y here to inject packet loss by discarding some received and some
|
|
transmitted packets.
|
|
|
|
config AF_RXRPC_INJECT_RX_DELAY
|
|
bool "Inject delay into packet reception"
|
|
depends on SYSCTL
|
|
help
|
|
Say Y here to inject a delay into packet reception, allowing an
|
|
extended RTT time to be modelled. The delay can be configured using
|
|
/proc/sys/net/rxrpc/rxrpc_inject_rx_delay, setting a number of
|
|
milliseconds up to 0.5s (note that the granularity is actually in
|
|
jiffies).
|
|
|
|
config AF_RXRPC_DEBUG
|
|
bool "RxRPC dynamic debugging"
|
|
help
|
|
Say Y here to make runtime controllable debugging messages appear.
|
|
|
|
See Documentation/networking/rxrpc.rst.
|
|
|
|
|
|
config RXKAD
|
|
bool "RxRPC Kerberos security"
|
|
help
|
|
Provide kerberos 4 and AFS kaserver security handling for AF_RXRPC
|
|
through the use of the key retention service.
|
|
|
|
See Documentation/networking/rxrpc.rst.
|
|
|
|
config RXGK
|
|
bool "RxRPC GSSAPI security"
|
|
select CRYPTO_KRB5
|
|
select CRYPTO_MANAGER
|
|
select CRYPTO_KRB5ENC
|
|
select CRYPTO_AUTHENC
|
|
select CRYPTO_SKCIPHER
|
|
select CRYPTO_HASH_INFO
|
|
select CRYPTO_HMAC
|
|
select CRYPTO_CMAC
|
|
select CRYPTO_SHA1
|
|
select CRYPTO_SHA256
|
|
select CRYPTO_SHA512
|
|
select CRYPTO_CBC
|
|
select CRYPTO_CTS
|
|
select CRYPTO_AES
|
|
select CRYPTO_CAMELLIA
|
|
help
|
|
Provide the GSSAPI-based RxGK security class for AFS. Keys are added
|
|
with add_key().
|
|
|
|
See Documentation/networking/rxrpc.rst.
|
|
|
|
config RXPERF
|
|
tristate "RxRPC test service"
|
|
help
|
|
Provide an rxperf service tester. This listens on UDP port 7009 for
|
|
incoming calls from the rxperf program (an example of which can be
|
|
found in OpenAFS).
|
|
|
|
config AF_RXRPC_KUNIT_TEST
|
|
tristate "RxRPC crypto KUnit test" if !KUNIT_ALL_TESTS
|
|
depends on KUNIT && RXKAD
|
|
default KUNIT_ALL_TESTS
|
|
help
|
|
Enable the KUnit test suite for RxRPC's crypto routines.
|
|
|
|
endif
|