<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://www.gentoo-zh.org/extern.php?action=feed&amp;tid=801&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Gentoo中文社区 / Linux/x86 6.6.13 内核配置选--Cryptographic API]]></title>
		<link>https://www.gentoo-zh.org/viewtopic.php?id=801</link>
		<description><![CDATA[Linux/x86 6.6.13 内核配置选--Cryptographic API 最近发表的帖子。]]></description>
		<lastBuildDate>Fri, 16 Feb 2024 03:58:11 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Linux/x86 6.6.13 内核配置选--Cryptographic API]]></title>
			<link>https://www.gentoo-zh.org/viewtopic.php?pid=916#p916</link>
			<description><![CDATA[<p>Crypto core or helper&#160; ---&gt;<br />翻译:<br />说明:</p><p>&#160; &#160; &#160; &#160; &#160; [ ] FIPS 200 compliance&#160; &#160;---&gt;<br />翻译:<br />说明:&quot;fips&quot;内核引导参数支持.这是在FIPS200认证的系统中运行所必须的.选&quot;N&quot;,除非你确实知道自己在做什么<br />&#160; &#160; &#160; &#160; &#160; (Linux Kernel Cryptographic API) FIPS Module Name<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Use Custom FIPS Module Version<br />&#160; &#160; &#160; &#160; &#160; - - Cryptographic algorithm manager<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Userspace cryptographic algorithm configuration<br />&#160; &#160; &#160; &#160; &#160; [ ] Disable run-time self tests<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Enable extra run-time crypto self tests<br />&#160; &#160; &#160; &#160; &#160; { } Null algorithms<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Parallel crypto engine<br />&#160; &#160; &#160; &#160; &#160; { } Software async crypto daemon<br />&#160; &#160; &#160; &#160; &#160; { } Authenc support<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Testing module</p><p>&#160; &#160; &#160; Public-key cryptography&#160; ---&gt;<br />翻译:<br />说明:非对称加密算法(公钥加密算法)<br />&#160; &#160; &#160; &#160; &#160; - - RSA (Rivest-Shamir-Adleman)<br />&#160; &#160; &#160; &#160; &#160; - - DH (Diffie-Hellman)<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;RFC 7919 FFDHE groups<br />&#160; &#160; &#160; &#160; &#160; { } ECDH (Elliptic Curve Diffie-Hellman)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; ECDSA (Elliptic Curve Digital Signature Algorithm)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; EC-RDSA (Elliptic Curve Russian Digital Signature Algorithm)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; SM2 (ShangMi 2)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Curve25519</p><p>&#160; &#160; &#160; Block ciphers&#160; ---&gt;<br />翻译:<br />说明:对敏感数据进行加密<br />&#160; &#160; &#160; &#160; &#160; - - AES (Advanced Encryption Standard)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; AES (Advanced Encryption Standard) (fixed time)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Anubis<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; ARIA<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Blowfish<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Camellia<br />&#160; &#160; &#160; &#160; &#160; { } CAST5 (CAST-128)<br />&#160; &#160; &#160; &#160; &#160; { } CAST6 (CAST-256)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; DES and Triple DES EDE<br />&#160; &#160; &#160; &#160; &#160; { } FCrypt<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Khazad<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; SEED<br />&#160; &#160; &#160; &#160; &#160; { } Serpent<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; SM4 (ShangMi 4)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; TEA, XTEA and XETA<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Twofish<br />&#160; &#160; &#160; Length-preserving ciphers and modes&#160; ---&gt;<br />翻译:<br />说明:保长密码和模式<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Adiantum phic API<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; ARC4 (Alleged Rivest Cipher 4)<br />&#160; &#160; &#160; &#160; &#160; { } ChaCha<br />&#160; &#160; &#160; &#160; &#160; - - CBC (Cipher Block Chaining)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; CFB (Cipher Feedback)<br />&#160; &#160; &#160; &#160; &#160; - - CTR (Counter)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; CTS (Cipher Text Stealing)<br />&#160; &#160; &#160; &#160; &#160; { } ECB (Electronic Codebook)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; HCTR2<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; KW (AES Key Wrap)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; LRW (Liskov Rivest Wagner)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; OFB (Output Feedback)<br />&#160; &#160; &#160; &#160; &#160; { } PCBC (Propagating Cipher Block Chaining)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; XTS (XOR Encrypt XOR with ciphertext stealing)<br />&#160; &#160; &#160; AEAD (authenticated encryption with associated data) ciphers&#160; ---&gt;<br />翻译:AEAD（具有相关数据的认证加密）密码 <br />说明:<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; AEGIS-128 hic API<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; ChaCha20-Poly1305<br />&#160; &#160; &#160; &#160; &#160; { } CCM (Counter with Cipher Block Chaining-MAC)<br />&#160; &#160; &#160; &#160; &#160; { } GCM (Galois/Counter Mode) and GMAC (GCM MAC)<br />&#160; &#160; &#160; &#160; &#160; { } Sequence Number IV Generator<br />&#160; &#160; &#160; &#160; &#160; { } Encrypted Chain IV Generator<br />&#160; &#160; &#160; &#160; &#160; { } Encrypted Salt-Sector IV Generator<br />&#160; &#160; &#160; Hashes, digests, and MACs&#160; ---&gt;<br />&#160; &#160; &#160; &#160; &#160; { } BLAKE2b aphic API<br />&#160; &#160; &#160; &#160; &#160; { } CMAC (Cipher-based MAC)<br />&#160; &#160; &#160; &#160; &#160; { } GHASH<br />&#160; &#160; &#160; &#160; &#160; - - HMAC (Keyed-Hash MAC)<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; MD4<br />&#160; &#160; &#160; &#160; &#160; - - MD5<br />&#160; &#160; &#160; &#160; &#160; { } Michael MIC<br />&#160; &#160; &#160; &#160; &#160; { } Poly1305<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; RIPEMD-160<br />&#160; &#160; &#160; &#160; &#160; - - SHA-1<br />&#160; &#160; &#160; &#160; &#160; - - SHA-224 and SHA-256<br />&#160; &#160; &#160; &#160; &#160; - - SHA-384 and SHA-512<br />&#160; &#160; &#160; &#160; &#160; - - SHA-3<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; SM3 (ShangMi 3)<br />&#160; &#160; &#160; &#160; &#160; { } Streebog<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; VMAC<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Whirlpool<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; XCBC-MAC (Extended Cipher Block Chaining MAC)<br />&#160; &#160; &#160; &#160; &#160; { } xxHash<br />&#160; &#160; &#160; CRCs (cyclic redundancy checks)&#160; ---&gt;<br />翻译:循环冗余校验<br />说明:</p><p>&#160; &#160; &#160; &#160; &#160; { } CRC32c raphic API<br />&#160; &#160; &#160; &#160; &#160; { } CRC32<br />&#160; &#160; &#160; &#160; &#160; - - CRCT10DIF<br />&#160; &#160; &#160; &#160; &#160; - - CRC64 based on Rocksoft Model algorithm<br />&#160; &#160; &#160; Compression&#160; ---&gt;<br />翻译:<br />说明:压缩算法</p><p>&#160; &#160; &#160; &#160; &#160; { } Deflate aphic API<br />&#160; &#160; &#160; &#160; &#160; - - LZO<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; 842<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; LZ4<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; LZ4HC<br />&#160; &#160; &#160; &#160; &#160; { } Zstd<br />&#160; &#160; &#160; Random number generation&#160; ---&gt;<br />翻译:<br />说明:符合ANSI(美国国家标准学会)X9.31-1998附录A.2.4所描述的伪随机数发生器(基于3DES).这是一种较老的算法,生成的随机数质量不高</p><p>&#160; &#160; &#160; &#160; &#160; &lt; &gt; ANSI PRNG (Pseudo Random Number Generator)<br />&#160; &#160; &#160; &#160; &#160; { } NIST SP800-90A DRBG (Deterministic Random Bit Generator)&#160; ---&gt;<br />&#160; &#160; &#160; &#160; &#160; - - CPU Jitter Non-Deterministic RNG (Random Number Generator)<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;CPU Jitter RNG Test Interface<br />&#160; &#160; &#160; Userspace interface&#160; ---&gt;<br />翻译:<br />说明:</p><p>&#160; &#160; &#160; &#160; &#160; - - Hash algorithms<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Symmetric key cipher algorithms<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; RNG (random number generator) algorithms<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Enable CAVP testing of DRBG<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; AEAD cipher algorithms<br />&#160; &#160; &#160; &#160; &#160; [ ] Obsolete cryptographic algorithms<br />&#160; &#160; &#160; &#160; &#160; [ ] Crypto usage statistics<br />&#160; &#160; &#160; Accelerated Cryptographic Algorithms for CPU (x86)&#160; ---&gt;<br />&#160; &#160; &#160; &#160; &#160; Ciphers&#160; Hash&#160; CRC32c CRCT10DIF<br />[ ]&#160; &#160;Hardware crypto devices&#160; ---&gt;<br />翻译:<br />说明:硬件加密设备支持</p><p>&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for VIA PadLock ACE<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160; &#160;PadLock driver for AES algorithm<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160; &#160;PadLock driver for SHA1 and SHA256 algorithms<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Microchip / Atmel ECC hw accelerator<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Microchip / Atmel SHA accelerator and RNG<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Support for AMD Secure Processor<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160; &#160;Secure Processor device driver<br />&#160; &#160; &#160; &#160; &#160; [ ] Cryptographic Coprocessor device<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt; Encryption and hashing offload support<br />&#160; &#160; &#160; &#160; &#160; [ ] Platform Security Processor (PSP) device<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160; &#160;Enable CCP Internals in DebugFS<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Cavium CNN55XX driver<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) DH895xCC<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) C3XXX<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) C62X<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) QAT_4XXX<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) DH895xCC Virtual Function<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) C3XXX Virtual Function<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for Intel(R) C62X Virtual Function<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Chelsio Crypto Co-processor Driver<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Inside Secure&#039;s SafeXcel cryptographic engine driver<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Support for amlogic cryptographic offloader&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;<br />- -&#160; &#160;Asymmetric (public-key cryptographic) key type&#160; ---&gt;<br />翻译:<br />说明:非对称加密算法(公钥加密算法)</p><p>&#160; &#160; &#160; &#160; &#160; --- Asymmetric (public-key cryptographic) key type<br />&#160; &#160; &#160; &#160; &#160; - -&#160; &#160;Asymmetric public-key crypto algorithm subtype<br />&#160; &#160; &#160; &#160; &#160; - -&#160; &#160; &#160;X.509 certificate parser<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160; &#160;PKCS#8 private key parser<br />&#160; &#160; &#160; &#160; &#160; - -&#160; &#160;PKCS#7 message parser<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;PKCS#7 testing key type<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Support for PE file signature verification<br />&#160; &#160; &#160; &#160; &#160; &lt; &gt;&#160; &#160;Run FIPS selftests on the X.509+PKCS7 signature verification<br />&#160; &#160; &#160; Certificates for signature checking&#160; ---&gt;<br />翻译:<br />说明:用于检查签名有效性的证书:(1)用于检查内核模块的签名,(2)用于检查全局密钥环(keyring)中的密钥的可靠性</p><p>&#160; &#160; &#160; &#160; &#160; (certs/signing_key.pem) File name or PKCS#11 URI of module signing key<br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; Type of module signing key to be generated (RSA)&#160; ---&gt;<br />&#160; &#160; &#160; &#160; &#160; - - Provide system-wide ring of trusted keys<br />&#160; &#160; &#160; &#160; &#160; ()&#160; &#160; Additional X.509 keys for default system keyring<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Reserve area for inserting a certificate without recompiling<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Provide a keyring to which extra trustable keys may be added<br />&#160; &#160; &#160; &#160; &#160; [ ] Provide system-wide ring of blacklisted keys<br />&#160; &#160; &#160; &#160; &#160; ()&#160; &#160; Hashes to be preloaded into the system blacklist keyring<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Provide system-wide ring of revocation certificates<br />&#160; &#160; &#160; &#160; &#160; [ ]&#160; &#160;Allow root to add signed blacklist keys</p>]]></description>
			<author><![CDATA[dummy@example.com (batsom)]]></author>
			<pubDate>Fri, 16 Feb 2024 03:58:11 +0000</pubDate>
			<guid>https://www.gentoo-zh.org/viewtopic.php?pid=916#p916</guid>
		</item>
	</channel>
</rss>
