No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Thorsten Leemhuis 24f8c991ad module: sign with sha512 instead of sha1 by default
commit f3b93547b91ad849b58eb5ab2dd070950ad7beb3 upstream.

Switch away from using sha1 for module signing by default and use the
more modern sha512 instead, which is what among others Arch, Fedora,
RHEL, and Ubuntu are currently using for their kernels.

Sha1 has not been considered secure against well-funded opponents since
2005[1]; since 2011 the NIST and other organizations furthermore
recommended its replacement[2]. This is why OpenSSL on RHEL9, Fedora
Linux 41+[3], and likely some other current and future distributions
reject the creation of sha1 signatures, which leads to a build error of
allmodconfig configurations:

  80A20474797F0000:error:03000098:digital envelope routines:do_sigver_init:invalid digest:crypto/evp/m_sigver.c:342:
  make[4]: *** [.../certs/Makefile:53: certs/signing_key.pem] Error 1
  make[4]: *** Deleting file 'certs/signing_key.pem'
  make[4]: *** Waiting for unfinished jobs....
  make[3]: *** [.../scripts/Makefile.build:478: certs] Error 2
  make[2]: *** [.../Makefile:1936: .] Error 2
  make[1]: *** [.../Makefile:224: __sub-make] Error 2
  make[1]: Leaving directory '...'
  make: *** [Makefile:224: __sub-make] Error 2

This change makes allmodconfig work again and sets a default that is
more appropriate for current and future users, too.

Link: https://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html [1]
Link: https://csrc.nist.gov/projects/hash-functions [2]
Link: https://fedoraproject.org/wiki/Changes/OpenSSLDistrustsha1SigVer [3]
Signed-off-by: Thorsten Leemhuis <linux@leemhuis.info>
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Tested-by: kdevops <kdevops@lists.linux.dev> [0]
Link: https://github.com/linux-kdevops/linux-modules-kpd/actions/runs/11420092929/job/31775404330 [0]
Link: https://lore.kernel.org/r/52ee32c0c92afc4d3263cea1f8a1cdc809728aff.1729088288.git.linux@leemhuis.info
Signed-off-by: Petr Pavlu <petr.pavlu@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-05-02 07:39:21 +02:00
arch perf/x86/intel/uncore: Fix the scale of IIO free running counters on SNR 2025-05-02 07:39:21 +02:00
block block: fix 'kmem_cache of name 'bio-108' already exists' 2025-04-10 14:29:37 +02:00
certs
crypto crypto: testmgr - some more fixes to RSA test vectors 2025-03-13 12:43:21 +01:00
Documentation sched/isolation: Prevent boot crash when the boot CPU is nohz_full 2025-04-10 14:29:35 +02:00
drivers i2c: cros-ec-tunnel: defer probe if parent EC is not present 2025-05-02 07:39:20 +02:00
fs virtiofs: add filesystem context source name check 2025-05-02 07:39:21 +02:00
include nfs: add missing selections of CONFIG_CRC32 2025-05-02 07:39:20 +02:00
init module: sign with sha512 instead of sha1 by default 2025-05-02 07:39:21 +02:00
ipc
kernel ftrace: Add cond_resched() to ftrace_graph_set_hash() 2025-05-02 07:39:17 +02:00
lib lib: scatterlist: fix sg_split_phys to preserve original scatterlist offsets 2025-05-02 07:39:15 +02:00
LICENSES
mm mm: add missing release barrier on PGDAT_RECLAIM_LOCKED unlock 2025-05-02 07:39:16 +02:00
net net: openvswitch: fix nested key length validation in the set() action 2025-05-02 07:39:19 +02:00
samples samples/bpf: Fix a resource leak 2024-12-14 19:44:50 +01:00
scripts selinux: Chain up tool resolving errors in install_policy.sh 2025-04-10 14:29:39 +02:00
security ima: Fix use-after-free on a dentry's dname.name 2025-03-13 12:43:19 +01:00
sound ALSA: usb-audio: Fix CME quirk for UF series keyboards 2025-05-02 07:39:10 +02:00
tools pm: cpupower: bench: Prevent NULL dereference on malloc failure 2025-05-02 07:39:09 +02:00
usr
virt KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status 2024-12-19 18:05:04 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore Remove *.orig pattern from .gitignore 2024-11-08 16:20:33 +01:00
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.292 2025-04-10 14:29:43 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.