Skip to content

Commit 05ce41f

Browse files
PlaidCatbmastbergen
authored andcommitted
configs: Ensure FIPS settings defined
We want to hard set the x86_64 FIPS required configs rather than rely on default settings in the kernel, should these ever change without our knowing it would not be something we would have actively checked. The configs are a limited set of configs that is expanded out when building using `make olddefconfig` a common practice in kernel building. Note had to manually add the following since its normaly set by the RPM build process. CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API" Signed-off-by: Jonathan Maple <jmaple@ciq.com>
1 parent 7c3a61a commit 05ce41f

File tree

2 files changed

+22
-0
lines changed

2 files changed

+22
-0
lines changed

configs/kernel-x86_64-debug-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7263,3 +7263,14 @@ CONFIG_ZSWAP=y
72637263
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72647264
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72657265
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7266+
7267+
CONFIG_X509_CERTIFICATE_PARSER=y
7268+
CONFIG_PKCS7_MESSAGE_PARSER=y
7269+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7270+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7271+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7272+
CONFIG_CRYPTO_DRBG=y
7273+
CONFIG_CRYPTO_FIPS=y
7274+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7275+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7276+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

configs/kernel-x86_64-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7240,3 +7240,14 @@ CONFIG_ZSWAP=y
72407240
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72417241
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72427242
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7243+
7244+
CONFIG_X509_CERTIFICATE_PARSER=y
7245+
CONFIG_PKCS7_MESSAGE_PARSER=y
7246+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7247+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7248+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7249+
CONFIG_CRYPTO_DRBG=y
7250+
CONFIG_CRYPTO_FIPS=y
7251+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7252+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7253+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

0 commit comments

Comments
 (0)