]> bbs.cooldavid.org Git - net-next-2.6.git/commit
random: Add optional continuous repetition test to entropy store based rngs
authorNeil Horman <nhorman@tuxdriver.com>
Thu, 18 Jun 2009 11:50:21 +0000 (19:50 +0800)
committerHerbert Xu <herbert@gondor.apana.org.au>
Thu, 18 Jun 2009 11:50:21 +0000 (19:50 +0800)
commit5b739ef8a4e8cf5201d21abff897e292c232477b
tree6301126016ad869997b4ef31973999e16049dfeb
parentb6f34d44cb341ad32f08717d1a2c418e6053a031
random: Add optional continuous repetition test to entropy store based rngs

FIPS-140 requires that all random number generators implement continuous self
tests in which each extracted block of data is compared against the last block
for repetition.  The ansi_cprng implements such a test, but it would be nice if
the hw rng's did the same thing.  Obviously its not something thats always
needed, but it seems like it would be a nice feature to have on occasion. I've
written the below patch which allows individual entropy stores to be flagged as
desiring a continuous test to be run on them as is extracted.  By default this
option is off, but is enabled in the event that fips mode is selected during
bootup.

Signed-off-by: Neil Horman <nhorman@tuxdriver.com>
Acked-by: Matt Mackall <mpm@selenic.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
crypto/internal.h
drivers/char/random.c
include/linux/fips.h [new file with mode: 0644]