Wiki - https://fedoraproject.org/wiki/Changes/Disable_CRYPTO_USER_API
Discussion thread -
https://discussion.fedoraproject.org/t/f45-change-proposal-disable-in-kernel-crypto-userspace-api-phase-1-self-contained/197422

This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.


== Summary ==
The in kernel Crypto Userspace API (CRYPTO_USER_API) is now deprecated
upstream, with some parts of it being actively removed early in the
7.2 cycle, because of the security risk it contains. It is due to be
disabled and actively removed from upstream in the near future.
Restrict it's use in Fedora to known active users early so we can do a
controlled ending of support and can make the community aware of it's
pending disappearance and gracefully deal with unknown users.

== Owner ==
* Name: [[User:pbrobinson| Peter Robinson]],  [[User:jforbes| Justin Forbes]]
* Email: [mailto:[email protected]
[email protected]], [mailto:[email protected]
[email protected]]


== Detailed Description ==
The in kernel Crypto Userspace API (CRYPTO_USER_API) is now deprecated
upstream, with some parts of it being actively removed early in the
7.2 cycle, because of the security risk it contains. It is due to be
disabled and actively removed from upstream in the near future. The
first phase will restrict it's use in Fedora early so we can do a
controlled ending of support and can make the community aware of it's
pending disappearance and gracefully deal with unknown users.

There's not a lot of known users of the in kernel Crypto Userspace API
so the impact should be minimal and there's upstream planning for most
of those.

The known Fedora users of the Crypto Userspace API are iwd, cryptsetup
(just used for 
[https://www.man7.org/linux/man-pages/man8/cryptsetup.8.html#TCRYPT_(TRUECRYPT_AND_VERACRYPT_COMPATIBLE)_EXTENSION
TrueCrypt, tcplay, or VeraCrypt] and some kernel level benchmarking)
and libkcapi (used by dracut, kernel build process). These users are
unaffected by this phase of the change. The cryptsetup already has the
ability to fall back to other mechanisms. The iwd users will continue
to function but users likely should migrate to wpa_supplicant (the iwd
package is currently unmaintained upstream).

The first phase uses the upstream patches due to land shortly, likely
in 7.3, to limit the use of the API to the known apps and restricts
the use. This allows Fedora to identify unknown users and gracefully
deal with them before the active demise of the interface upstream
providing users a more graceful process rather than universally
pulling the rug without any notice.

== Benefit to Fedora ==

The benefit to Fedora is to allow users of the in kernel crypto API to
be aware of the impending disappearance of the interface and to give
them some time to gracefully migrate to other userspace interfaces
before the API is gone for good.

== Scope ==
* Proposal owners:
** Ensure all the components that use the crypto userspace APIs have
migrated to other userspace crypto APIs.
** Document the the replacements

* Other developers:
** No impact

* Release engineering: [https://pagure.io/releng/issue/XXXX #XXXX]
** 
[[Fedora_Program_Management/ReleaseBlocking/Fedora{{FedoraVersionNumber|next}}|List
of deliverables]]: N/A (not a System Wide Change)

* Policies and guidelines: N/A (not a System Wide Change)

* Trademark approval: N/A (not needed for this Change)


== Upgrade/compatibility impact ==
No current known users of the crypto userspace kAPIs are affected and
will continue to work. There may be third party users which will be
identified as part of this process to allow us to work with them to
mitigate/migrate to more suitable interfaces.

== How To Test ==

* Install a Fedora 7.2 kernel build

== User Experience ==

Generally users should not notice. The kernel Crypto Userspace API was
never widely used and the in Fedora packages that make use of it will
migrate to other mechanisms without users being aware of the change.

== Dependencies ==
No external dependencies.

== Contingency Plan ==

* Contingency mechanism: Re-enable
* Contingency deadline: GA
* Blocks release? No.
* Blocks product? No.

== Documentation ==
There's no specific kernel Crypto Userspace API documentation in Fedora.

== Release Notes ==
Fedora has actively deprecated the in kernel Crypto Userspace API and
no longer actively supports it's use. If you currently use the
userspace crypto API please migrate to another suitable userspace
crypto API.


-- 
Aoife Moloney

Fedora Operations Architect

Fedora Project

Matrix: @amoloney:fedora.im

IRC: amoloney

-- 
_______________________________________________
devel-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to