]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
sctp: Stop accepting md5 and sha1 for net.sctp.cookie_hmac_alg
authorEric Biggers <ebiggers@kernel.org>
Mon, 18 Aug 2025 20:54:26 +0000 (13:54 -0700)
committerJakub Kicinski <kuba@kernel.org>
Wed, 20 Aug 2025 02:36:26 +0000 (19:36 -0700)
commitd5a253702add0da3e1e19252ae2a251ee24b486d
treea77462f438da5b5b58a17573c4346fdc1e4aa725
parent2f3dd6ec901f29aef5fff3d7a63b1371d67c1760
sctp: Stop accepting md5 and sha1 for net.sctp.cookie_hmac_alg

The upgrade of the cookie authentication algorithm to HMAC-SHA256 kept
some backwards compatibility for the net.sctp.cookie_hmac_alg sysctl by
still accepting the values 'md5' and 'sha1'.  Those algorithms are no
longer actually used, but rather those values were just treated as
requests to enable cookie authentication.

As requested at
https://lore.kernel.org/netdev/CADvbK_fmCRARc8VznH8cQa-QKaCOQZ6yFbF=1-VDK=zRqv_cXw@mail.gmail.com/
and https://lore.kernel.org/netdev/20250818084345.708ac796@kernel.org/ ,
go further and start rejecting 'md5' and 'sha1' completely.

Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Link: https://patch.msgid.link/20250818205426.30222-6-ebiggers@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Documentation/networking/ip-sysctl.rst
net/sctp/sysctl.c