Skip to content

Commit 7d1d965

Browse files
committed
configs: Ensure FIPS settings defined
We want to hard set the x86_64 FIPS required configs rather than rely on default settings in the kernel, should these ever change without our knowing it would not be something we would have actively checked. The configs are a limited set of configs that is expanded out when building using `make olddefconfig` a common practice in kernel building. Note had to manually add the following since its normaly set by the RPM build process. CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API" Signed-off-by: Jonathan Maple <[email protected]>
1 parent fd8a0de commit 7d1d965

File tree

2 files changed

+22
-0
lines changed

2 files changed

+22
-0
lines changed

configs/kernel-x86_64-debug-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7193,3 +7193,14 @@ CONFIG_ZSWAP=y
71937193
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
71947194
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
71957195
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7196+
7197+
CONFIG_X509_CERTIFICATE_PARSER=y
7198+
CONFIG_PKCS7_MESSAGE_PARSER=y
7199+
ONFIG_FIPS_SIGNATURE_SELFTEST=y
7200+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7201+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7202+
CONFIG_CRYPTO_DRBG=y
7203+
CONFIG_CRYPTO_FIPS=y
7204+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7205+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7206+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

configs/kernel-x86_64-rhel.config

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7170,3 +7170,14 @@ CONFIG_ZSWAP=y
71707170
# CONFIG_ZSWAP_ZPOOL_DEFAULT_Z3FOLD is not set
71717171
CONFIG_ZSWAP_ZPOOL_DEFAULT_ZBUD=y
71727172
# CONFIG_ZSWAP_ZPOOL_DEFAULT_ZSMALLOC is not set
7173+
7174+
CONFIG_X509_CERTIFICATE_PARSER=y
7175+
CONFIG_PKCS7_MESSAGE_PARSER=y
7176+
CONFIG_FIPS_SIGNATURE_SELFTEST=y
7177+
CONFIG_FIPS_SIGNATURE_SELFTEST_RSA=y
7178+
CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA=y
7179+
CONFIG_CRYPTO_DRBG=y
7180+
CONFIG_CRYPTO_FIPS=y
7181+
CONFIG_CRYPTO_FIPS_CUSTOM_VERSION=y
7182+
CONFIG_CRYPTO_FIPS_VERSION="rocky9.20250725"
7183+
CONFIG_CRYPTO_FIPS_NAME="Rocky Linux 9 Kernel Cryptographic API"

0 commit comments

Comments
 (0)