Wiki - https://fedoraproject.org/wiki/Changes/Disable_CRYPTO_USER_API Discussion thread - https://discussion.fedoraproject.org/t/f45-change-proposal-disable-in-kernel-crypto-userspace-api-phase-1-self-contained/197422 This is a proposed Change for Fedora Linux. This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering Steering Committee. == Summary == The in kernel Crypto Userspace API (CRYPTO_USER_API) is now deprecated upstream, with some parts of it being actively removed early in the 7.2 cycle, because of the security risk it contains. It is due to be disabled and actively removed from upstream in the near future. Restrict it's use in Fedora to known active users early so we can do a controlled ending of support and can make the community aware of it's pending disappearance and gracefully deal with unknown users. == Owner == * Name: [[User:pbrobinson| Peter Robinson]], [[User:jforbes| Justin Forbes]] * Email: [mailto:pbrobinson@fedoraproject.org pbrobinson@fedoraproject.org], [mailto:jforbes@fedoraproject.org jforbes@fedoraproject.org] == Detailed Description == The in kernel Crypto Userspace API (CRYPTO_USER_API) is now deprecated upstream, with some parts of it being actively removed early in the 7.2 cycle, because of the security risk it contains. It is due to be disabled and actively removed from upstream in the near future. The first phase will restrict it's use in Fedora early so we can do a controlled ending of support and can make the community aware of it's pending disappearance and gracefully deal with unknown users. There's not a lot of known users of the in kernel Crypto Userspace API so the impact should be minimal and there's upstream planning for most of those. The known Fedora users of the Crypto Userspace API are iwd, cryptsetup (just used for [https://www.man7.org/linux/man-pages/man8/cryptsetup.8.html#TCRYPT_(TRUECRYPT_AND_VERACRYPT_COMPATIBLE)_EXTENSION TrueCrypt, tcplay, or VeraCrypt] and some kernel level benchmarking) and libkcapi (used by dracut, kernel build process). These users are unaffected by this phase of the change. The cryptsetup already has the ability to fall back to other mechanisms. The iwd users will continue to function but users likely should migrate to wpa_supplicant (the iwd package is currently unmaintained upstream). The first phase uses the upstream patches due to land shortly, likely in 7.3, to limit the use of the API to the known apps and restricts the use. This allows Fedora to identify unknown users and gracefully deal with them before the active demise of the interface upstream providing users a more graceful process rather than universally pulling the rug without any notice. == Benefit to Fedora == The benefit to Fedora is to allow users of the in kernel crypto API to be aware of the impending disappearance of the interface and to give them some time to gracefully migrate to other userspace interfaces before the API is gone for good. == Scope == * Proposal owners: ** Ensure all the components that use the crypto userspace APIs have migrated to other userspace crypto APIs. ** Document the the replacements * Other developers: ** No impact * Release engineering: [https://pagure.io/releng/issue/XXXX #XXXX] ** [[Fedora_Program_Management/ReleaseBlocking/Fedora{{FedoraVersionNumber|next}}|List of deliverables]]: N/A (not a System Wide Change) * Policies and guidelines: N/A (not a System Wide Change) * Trademark approval: N/A (not needed for this Change) == Upgrade/compatibility impact == No current known users of the crypto userspace kAPIs are affected and will continue to work. There may be third party users which will be identified as part of this process to allow us to work with them to mitigate/migrate to more suitable interfaces. == How To Test == * Install a Fedora 7.2 kernel build == User Experience == Generally users should not notice. The kernel Crypto Userspace API was never widely used and the in Fedora packages that make use of it will migrate to other mechanisms without users being aware of the change. == Dependencies == No external dependencies. == Contingency Plan == * Contingency mechanism: Re-enable * Contingency deadline: GA * Blocks release? No. * Blocks product? No. == Documentation == There's no specific kernel Crypto Userspace API documentation in Fedora. == Release Notes == Fedora has actively deprecated the in kernel Crypto Userspace API and no longer actively supports it's use. If you currently use the userspace crypto API please migrate to another suitable userspace crypto API. -- Aoife Moloney Fedora Operations Architect Fedora Project Matrix: @amoloney:fedora.im IRC: amoloney -- _______________________________________________ devel-announce mailing list -- devel-announce@lists.fedoraproject.org To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
No comments:
Post a Comment