Re: [PATCH 01/19] User-space API definition

From: Kyle Moffett
Date: Sat Aug 21 2010 - 09:10:27 EST


On Fri, Aug 20, 2010 at 04:45, Miloslav TrmaÄ <mitr@xxxxxxxxxx> wrote:
> This patch introduces the new user-space API, <ncr.h>.
>
> Quick overview:
>
> * open("/dev/crypto") to get a FD, which acts as a namespace for key and
> Âsession identifiers.
>
> * ioctl(NCRIO_KEY_INIT) to allocate a key object; then generate the key
> Âmaterial inside the kernel, load a plaintext key, unwrap a key, or
> Âderive a key. ÂSimilarly the key material can be copied out of the
> Âkernel or wrapped.
>
> [...snip...]

Ugh... We already have one very nice key/keyring API in the kernel
(see Documentation/keys.txt) that's being used for crypto keys for
NFSv4, AFS, etc. Can't you just add a bunch of cryptoapi key types to
that API instead?

David Howells added to CC, since I believe he wrote most of that code initially.

Cheers,
Kyle Moffett
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/