Skip to content

Commit 12461db

Browse files
rphillipsbertinatto
authored andcommitted
UPSTREAM: <carry>: disable AES24, not supported by FIPS
OpenShift-Rebase-Source: b9a8eb6
1 parent 87a7fa2 commit 12461db

File tree

1 file changed

+5
-3
lines changed
  • staging/src/k8s.io/apiserver/pkg/storage/value/encrypt/aes

1 file changed

+5
-3
lines changed

staging/src/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes_test.go

+5-3
Original file line numberDiff line numberDiff line change
@@ -730,10 +730,12 @@ func TestRoundTrip(t *testing.T) {
730730
if err != nil {
731731
t.Fatal(err)
732732
}
733-
aes24block, err := aes.NewCipher(bytes.Repeat([]byte("b"), 24))
733+
/* FIPS disabled
734+
aes24block, err := aes.NewCipher([]byte(bytes.Repeat([]byte("b"), 24)))
734735
if err != nil {
735736
t.Fatal(err)
736737
}
738+
*/
737739
key32 := bytes.Repeat([]byte("c"), 32)
738740
aes32block, err := aes.NewCipher(key32)
739741
if err != nil {
@@ -746,10 +748,10 @@ func TestRoundTrip(t *testing.T) {
746748
t value.Transformer
747749
}{
748750
{name: "GCM 16 byte key", t: newGCMTransformer(t, aes16block, nil)},
749-
{name: "GCM 24 byte key", t: newGCMTransformer(t, aes24block, nil)},
751+
// FIPS disabled {name: "GCM 24 byte key", t: newGCMTransformer(t, aes24block, nil)},
750752
{name: "GCM 32 byte key", t: newGCMTransformer(t, aes32block, nil)},
751753
{name: "GCM 16 byte unsafe key", t: newGCMTransformerWithUniqueKeyUnsafeTest(t, aes16block, nil)},
752-
{name: "GCM 24 byte unsafe key", t: newGCMTransformerWithUniqueKeyUnsafeTest(t, aes24block, nil)},
754+
// FIPS disabled {name: "GCM 24 byte unsafe key", t: newGCMTransformerWithUniqueKeyUnsafeTest(t, aes24block, nil)},
753755
{name: "GCM 32 byte unsafe key", t: newGCMTransformerWithUniqueKeyUnsafeTest(t, aes32block, nil)},
754756
{name: "GCM 32 byte seed", t: newHKDFExtendedNonceGCMTransformerTest(t, nil, key32)},
755757
{name: "CBC 32 byte key", t: NewCBCTransformer(aes32block)},

0 commit comments

Comments
 (0)