Skip to content

Commit 53adb35

Browse files
PlaidCatshreeya-patel98
authored andcommitted
configs: Ensure FIPS settings defined
We want to hard set the x86_64 FIPS required configs rather than rely on default settings in the kernel, should these ever change without our knowing it would not be something we would have actively checked. The configs are a limited set of configs that is expanded out when building using `make olddefconfig` a common practice in kernel building. Note had to manually add the following since its normaly set by the RPM build process. CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API" Signed-off-by: Jonathan Maple <[email protected]> Signed-off-by: Shreeya Patel <[email protected]>
1 parent 73ffaa3 commit 53adb35

File tree

2 files changed

+22
-0
lines changed

2 files changed

+22
-0
lines changed

configs/kernel-x86_64-debug-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7260,3 +7260,14 @@ CONFIG_ZSWAP=y
72607260
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72617261
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72627262
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7263+
7264+
CONFIG_X509_CERTIFICATE_PARSER=y
7265+
CONFIG_PKCS7_MESSAGE_PARSER=y
7266+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7267+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7268+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7269+
CONFIG_CRYPTO_DRBG=y
7270+
CONFIG_CRYPTO_FIPS=y
7271+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7272+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7273+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

configs/kernel-x86_64-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7237,3 +7237,14 @@ CONFIG_ZSWAP=y
72377237
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72387238
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72397239
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7240+
7241+
CONFIG_X509_CERTIFICATE_PARSER=y
7242+
CONFIG_PKCS7_MESSAGE_PARSER=y
7243+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7244+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7245+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7246+
CONFIG_CRYPTO_DRBG=y
7247+
CONFIG_CRYPTO_FIPS=y
7248+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7249+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7250+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

0 commit comments

Comments
 (0)