Skip to content

Commit b9a8eb6

Browse files
rphillipssoltysh
authored andcommittedSep 20, 2022
UPSTREAM: <carry>: disable AES24, not supported by FIPS
Origin-commit: beac12d815b4099cfd4f4d953da4b8789054be51 openshift-rebase(v1.24):source=198209159d4
1 parent a137009 commit b9a8eb6

File tree

1 file changed

+3
-1
lines changed
  • staging/src/k8s.io/apiserver/pkg/storage/value/encrypt/aes

1 file changed

+3
-1
lines changed
 

‎staging/src/k8s.io/apiserver/pkg/storage/value/encrypt/aes/aes_test.go

+3-1
Original file line numberDiff line numberDiff line change
@@ -371,10 +371,12 @@ func TestRoundTrip(t *testing.T) {
371371
if err != nil {
372372
t.Fatal(err)
373373
}
374+
/* FIPS disabled
374375
aes24block, err := aes.NewCipher([]byte(bytes.Repeat([]byte("b"), 24)))
375376
if err != nil {
376377
t.Fatal(err)
377378
}
379+
*/
378380
aes32block, err := aes.NewCipher([]byte(bytes.Repeat([]byte("c"), 32)))
379381
if err != nil {
380382
t.Fatal(err)
@@ -387,7 +389,7 @@ func TestRoundTrip(t *testing.T) {
387389
t value.Transformer
388390
}{
389391
{name: "GCM 16 byte key", t: NewGCMTransformer(aes16block)},
390-
{name: "GCM 24 byte key", t: NewGCMTransformer(aes24block)},
392+
// FIPS disabled {name: "GCM 24 byte key", t: NewGCMTransformer(aes24block)},
391393
{name: "GCM 32 byte key", t: NewGCMTransformer(aes32block)},
392394
{name: "CBC 32 byte key", t: NewCBCTransformer(aes32block)},
393395
}

0 commit comments

Comments
 (0)
Please sign in to comment.