提交 ed6f76b4 编写于 作者: T Tony Krowiak 提交者: Christian Borntraeger

KVM: s390/cpacf: Enable key wrapping by default

z/VM and LPAR enable key wrapping by default, lets do the same on KVM.
Signed-off-by: NTony Krowiak <akrowiak@linux.vnet.ibm.com>
Signed-off-by: NChristian Borntraeger <borntraeger@de.ibm.com>
上级 c517d838
...@@ -839,9 +839,13 @@ static int kvm_s390_crypto_init(struct kvm *kvm) ...@@ -839,9 +839,13 @@ static int kvm_s390_crypto_init(struct kvm *kvm)
kvm_s390_set_crycb_format(kvm); kvm_s390_set_crycb_format(kvm);
/* Disable AES/DEA protected key functions by default */ /* Enable AES/DEA protected key functions by default */
kvm->arch.crypto.aes_kw = 0; kvm->arch.crypto.aes_kw = 1;
kvm->arch.crypto.dea_kw = 0; kvm->arch.crypto.dea_kw = 1;
get_random_bytes(kvm->arch.crypto.crycb->aes_wrapping_key_mask,
sizeof(kvm->arch.crypto.crycb->aes_wrapping_key_mask));
get_random_bytes(kvm->arch.crypto.crycb->dea_wrapping_key_mask,
sizeof(kvm->arch.crypto.crycb->dea_wrapping_key_mask));
return 0; return 0;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册