From: Tushar Gohad Date: Thu, 28 Jul 2011 10:36:20 +0000 (+0000) Subject: xfrm: Fix key lengths for rfc3686(ctr(aes)) X-Git-Tag: v2.6.32.51~10 X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=57cc6e02424b967f70a4270e4f059d3b9d684605;p=linux-pvops.git xfrm: Fix key lengths for rfc3686(ctr(aes)) commit 4203223a1aed862b4445fdcd260d6139603a51d9 upstream. Fix the min and max bit lengths for AES-CTR (RFC3686) keys. The number of bits in key spec is the key length (128/256) plus 32 bits of nonce. This change takes care of the "Invalid key length" errors reported by setkey when specifying 288 bit keys for aes-ctr. Signed-off-by: Tushar Gohad Acked-by: Herbert Xu Signed-off-by: David S. Miller Signed-off-by: Calvin Owens Signed-off-by: Greg Kroah-Hartman --- diff --git a/net/xfrm/xfrm_algo.c b/net/xfrm/xfrm_algo.c index faf54c6bf96b..9bd850a86844 100644 --- a/net/xfrm/xfrm_algo.c +++ b/net/xfrm/xfrm_algo.c @@ -411,8 +411,8 @@ static struct xfrm_algo_desc ealg_list[] = { .desc = { .sadb_alg_id = SADB_X_EALG_AESCTR, .sadb_alg_ivlen = 8, - .sadb_alg_minbits = 128, - .sadb_alg_maxbits = 256 + .sadb_alg_minbits = 160, + .sadb_alg_maxbits = 288 } }, };