Re: [PATCH] Allow hmac(sha512) for unpriviledged users
From: Eric Biggers
Date: Sat Oct 03 2026 - 12:19:35 EST
On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> By default users cannot run sha512hmac with the current set up. This
> is problematic because our kernel builds call this for FIPS compliance.
> Rather than have anyone turn off af_alg_restrict all together, let's
> allow a common use case.
>
> Signed-off-by: Justin M. Forbes <jforbes@xxxxxxxxxxxxxxxxx>
The fips hook in dracut was taken into account already, and it runs as
root. So this patch shouldn't be needed. Can you clarify why you think
it is needed?
- Eric