]> www.infradead.org Git - users/dwmw2/linux.git/commit
module: Do not offer sha224 for built-in module signing
authorDimitri John Ledkov <dimitri.ledkov@canonical.com>
Tue, 10 Oct 2023 21:26:33 +0000 (22:26 +0100)
committerHerbert Xu <herbert@gondor.apana.org.au>
Fri, 20 Oct 2023 05:39:26 +0000 (13:39 +0800)
commitfc3225fd6f1e6ac07a8463e7751ecfa228880c71
tree9a80464a88b4a173b10c930bd0ec83f6f297237c
parentc1d760a47163bec1ecd5c82638c8c234fcbd549e
module: Do not offer sha224 for built-in module signing

sha224 does not provide enough security against collision attacks
relative to the default keys used for signing (RSA 4k & P-384). Also
sha224 never became popular, as sha256 got widely adopter ahead of
sha224 being introduced.

Signed-off-by: Dimitri John Ledkov <dimitri.ledkov@canonical.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
kernel/module/Kconfig