s390/crypto: Extend key length check for AES-XTS in fips mode.
authorHarald Freudenberger <freude@linux.vnet.ibm.com>
Sat, 7 Oct 2017 22:36:57 +0000 (22:36 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 8 Nov 2017 09:08:37 +0000 (10:08 +0100)
commitc31f5651aed76791782e7a0c74fe301ed8f9391e
treed082a17296e5e8862c32a51578b25ddf536e784f
parentaa7a7e92e08e1f096a0eb63fb535d03c323b32e5
s390/crypto: Extend key length check for AES-XTS in fips mode.

[ Upstream commit a4f2779ecf2f42b0997fedef6fd20a931c40a3e3 ]

In fips mode only xts keys with 128 bit or 125 bit are allowed.
This fix extends the xts_aes_set_key function to check for these
valid key lengths in fips mode.

Signed-off-by: Harald Freudenberger <freude@linux.vnet.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
arch/s390/crypto/aes_s390.c