Skip to content

Conversation

jallisonciq
Copy link

…DRBG"

JIRA: INTERNAL
Revert Author <jallison@ciq.com>
Revert Commit fd8a0deb716f6f4dde224de4a6e1caa08cef801d.
Revert Reason: This changes the default DRBG back to HMAC SHA512 to
keep entropy certifications for all Rocky9.6 FIPS modules.
Approved by the lab.

Keeping hmac(sha512) allows the entropy certificates used for Rocky 9.2 FIPS to be re-used in 9.6, preventing re-certification of all the kernel and userspace modules.

NB. We still get the scalability speedup from the per-CPU DRBG changes.

…DRBG"

    JIRA: INTERNAL
    Revert Author <jallison@ciq.com>
    Revert Commit fd8a0de.
    Revert Reason: This changes the default DRBG back to HMAC SHA512 to
    keep entropy certifications for all Rocky9.6 FIPS modules.
    Approved by the lab.

Keeping hmac(sha512) allows the entropy certificates used
for Rocky 9.2 FIPS to be re-used in 9.6, preventing re-certification
of all the kernel and userspace modules.

NB. We still get the scalability speedup from the per-CPU DRBG
changes.

Signed-off-by: Jeremy Allison <jallison@ciq.com>
Copy link
Collaborator

@bmastbergen bmastbergen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@jallisonciq jallisonciq merged commit bdb6649 into fips-9-compliant/5.14.0-570.33.2.el9_6 Sep 3, 2025
4 checks passed
@jallisonciq jallisonciq deleted the {jallison}-revert-conditioning-change-fips-9-compliant/5.14.0-570.33.2.el9_6 branch September 3, 2025 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants