]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
crypto: drbg - Change DRBG_MAX_REQUESTS to 4096
authorEric Biggers <ebiggers@kernel.org>
Mon, 20 Apr 2026 06:34:19 +0000 (23:34 -0700)
committerHerbert Xu <herbert@gondor.apana.org.au>
Thu, 7 May 2026 08:10:01 +0000 (16:10 +0800)
commit005b19f18ea9fc51fc35fbcb27759ae83c7c89f8
tree909be7b6696a2bbbe61ed65bb4e1182abaec9bc0
parentca659874af31c6c6e1c5992475b88be8cb65d484
crypto: drbg - Change DRBG_MAX_REQUESTS to 4096

Currently a formal reseed happens only after each 1048576 requests.

That's quite a high number.  Let's follow the example of BoringSSL and
use a more conservative value of 4096.

Note that in practice this makes little difference, now that we're
including 32 bytes from get_random_bytes() in the additional input on
every request anyway, which is a de facto reseed.

But for the same reason, we might as well decrease the actual reseed
interval to something more reasonable.

Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
crypto/drbg.c