mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
zkey: Adjust the error message when calculating the KVP fails
The 'paes' and 'phmac' kernel ciphers and the respective kernel modules are no longer used for calculating the key verification pattern. Instead, the 'pkey' kernel module and its sub modules is used now. In case the 'pkey' kernel module is not available, an appropriate error message is already printed by open_pkey_device() when opening the device. Reviewed-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
7fffdcfe8c
commit
584e785f5c
@@ -2101,10 +2101,6 @@ static int _keystore_create_info_file(struct keystore *keystore,
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the key verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key_type(key_type) ? "paes_s390" : "phmac_s390",
|
||||
is_aes_key_type(key_type) ? "paes" : "phmac");
|
||||
remove(filenames->pass_filename);
|
||||
goto out;
|
||||
}
|
||||
@@ -2400,10 +2396,6 @@ int keystore_generate_key_kms(struct keystore *keystore, const char *name,
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the key verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key_type(key_type) ? "paes_s390" : "phmac_s390",
|
||||
is_aes_key_type(key_type) ? "paes" : "phmac");
|
||||
goto out_free_props;
|
||||
}
|
||||
|
||||
@@ -3913,12 +3905,6 @@ static int _keystore_process_reencipher(struct keystore *keystore,
|
||||
warnx("Failed to generate the key verification pattern "
|
||||
"for key '%s': %s", file_names->skey_filename,
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes_s390" : "phmac_s390",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes" : "phmac");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -6170,12 +6156,6 @@ prompt_alt_name:
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the key verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes_s390" : "phmac_s390",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes" : "phmac");
|
||||
fatal_err = true;
|
||||
goto out_remove;
|
||||
}
|
||||
|
||||
@@ -3451,12 +3451,6 @@ int refresh_kms_key(struct kms_info *kms_info, struct properties *key_props,
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key(key_blob, key_blob_size) ?
|
||||
"paes_s390" : "phmac_s390",
|
||||
is_aes_key(key_blob, key_blob_size) ?
|
||||
"paes" : "phmac");
|
||||
goto out;
|
||||
}
|
||||
|
||||
|
||||
@@ -1974,8 +1974,6 @@ static int reencipher_prepare(int token)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'paes_s390' is loaded and "
|
||||
"that the 'paes' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -1991,9 +1989,6 @@ static int reencipher_prepare(int token)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'phmac_s390' is "
|
||||
"loaded and that the 'phmac' cipher is "
|
||||
"available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -2188,8 +2183,6 @@ static int reencipher_complete(int token)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'paes_s390' is loaded and "
|
||||
"that the 'paes' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -2208,9 +2201,6 @@ static int reencipher_complete(int token)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'phmac_s390' is "
|
||||
"loaded and that the 'phmac' cipher is "
|
||||
"available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -2530,8 +2520,6 @@ static int command_setvp(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'paes_s390' is loaded and "
|
||||
"that the 'paes' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -2546,8 +2534,6 @@ static int command_setvp(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'phmac_s390' is "
|
||||
"loaded and that the 'phmac' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
@@ -2701,8 +2687,6 @@ static int command_setkey(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'paes_s390' is loaded and "
|
||||
"that the 'paes' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -2715,9 +2699,6 @@ static int command_setkey(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'phmac_s390' is "
|
||||
"loaded and that the 'phmac' cipher is "
|
||||
"available");
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
@@ -2985,8 +2966,6 @@ static int command_convert(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'paes_s390' is loaded and "
|
||||
"that the 'paes' cipher is available");
|
||||
goto out;
|
||||
}
|
||||
|
||||
@@ -3000,9 +2979,6 @@ static int command_convert(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module 'phmac_s390' is "
|
||||
"loaded and that the 'phmac' cipher is "
|
||||
"available");
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2503,12 +2503,6 @@ static int command_validate_file(void)
|
||||
if (rc != 0) {
|
||||
warnx("Failed to generate the verification pattern: %s",
|
||||
strerror(-rc));
|
||||
warnx("Make sure that kernel module '%s' is loaded and "
|
||||
"that the '%s' cipher is available",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes_s390" : "phmac_s390",
|
||||
is_aes_key(secure_key, secure_key_size) ?
|
||||
"paes" : "phmac");
|
||||
rc = EXIT_FAILURE;
|
||||
goto out;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user