[PATCH] KEYS: encrypted: Remove unnecessary selection of CRYPTO_RNG
From: Eric Biggers
Date: Sat Mar 21 2026 - 18:43:57 EST
encrypted-keys uses the regular Linux RNG (get_random_bytes()), not the
duplicative crypto_rng one. So it does not need to select CRYPTO_RNG.
Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
---
This patch is targeting the keyrings tree
security/keys/Kconfig | 1 -
1 file changed, 1 deletion(-)
diff --git a/security/keys/Kconfig b/security/keys/Kconfig
index 84f39e50ca36..f4510d8cb485 100644
--- a/security/keys/Kconfig
+++ b/security/keys/Kconfig
@@ -85,11 +85,10 @@ config ENCRYPTED_KEYS
tristate "ENCRYPTED KEYS"
select CRYPTO
select CRYPTO_AES
select CRYPTO_CBC
select CRYPTO_LIB_SHA256
- select CRYPTO_RNG
help
This option provides support for create/encrypting/decrypting keys
in the kernel. Encrypted keys are instantiated using kernel
generated random numbers or provided decrypted data, and are
encrypted/decrypted with a 'master' symmetric key. The 'master'
base-commit: 113ae7b4decc6c2d95bdbbe52e615a0137ef7f9f
--
2.53.0