Skip to content

Commit 487c54b

Browse files
committed
configs: Ensure FIPS settings defined
We want to hard set the x86_64 FIPS required configs rather than rely on default settings in the kernel, should these ever change without our knowing it would not be something we would have actively checked. The configs are a limited set of configs that is expanded out when building using `make olddefconfig` a common practice in kernel building. Note had to manually add the following since its normaly set by the RPM build process. CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API" Signed-off-by: Jonathan Maple <jmaple@ciq.com>
1 parent ca0ea44 commit 487c54b

File tree

2 files changed

+22
-0
lines changed

2 files changed

+22
-0
lines changed

configs/kernel-x86_64-debug-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7260,3 +7260,14 @@ CONFIG_ZSWAP=y
72607260
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72617261
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72627262
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7263+
7264+
CONFIG_X509_CERTIFICATE_PARSER=y
7265+
CONFIG_PKCS7_MESSAGE_PARSER=y
7266+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7267+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7268+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7269+
CONFIG_CRYPTO_DRBG=y
7270+
CONFIG_CRYPTO_FIPS=y
7271+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7272+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7273+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

configs/kernel-x86_64-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7237,3 +7237,14 @@ CONFIG_ZSWAP=y
72377237
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
72387238
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
72397239
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7240+
7241+
CONFIG_X509_CERTIFICATE_PARSER=y
7242+
CONFIG_PKCS7_MESSAGE_PARSER=y
7243+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7244+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7245+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7246+
CONFIG_CRYPTO_DRBG=y
7247+
CONFIG_CRYPTO_FIPS=y
7248+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7249+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7250+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

0 commit comments

Comments
 (0)