Re: [PATCH] Allow hmac(sha512) for unpriviledged users

From: Justin Forbes

Date: Sat Oct 03 2026 - 13:23:45 EST


On Sat, Oct 03, 2026 at 06:18:59PM +0200, Eric Biggers wrote:
> On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> > By default users cannot run sha512hmac with the current set up. This
> > is problematic because our kernel builds call this for FIPS compliance.
> > Rather than have anyone turn off af_alg_restrict all together, let's
> > allow a common use case.
> >
> > Signed-off-by: Justin M. Forbes <jforbes@xxxxxxxxxxxxxxxxx>
>
> The fips hook in dracut was taken into account already, and it runs as
> root. So this patch shouldn't be needed. Can you clarify why you think
> it is needed?
>
> - Eric

Specifically for the case of Fedora and all Red Hat kernels, we call
sha512hmac to sign the kernel, and a couple of UKI images that are
created during the kernel build. Users on Fedora 45 and newer are now
unable to build the kernel from spec without turning off af_alg_restrict
all together, while any user can build a kernel on Fedora 44 or older.

Justin