freebsd-dev/lib/geom/eli
Mariusz Zaborski 5fff09660e geli: split the initalization of HMAC
GELI allows to read a user key from a standard input.
However if user initialize multiple providers at once, the standard
input will be empty for the second and next providers.
This caused GELI to encrypt a master key with an empty key file.

This commits initialize the HMAC with the key file, and then reuse the
finalized structure to generate different encryption keys for different
providers.

Reported by:	Nathan Dorfman
Tested by:	philip
Security:	FreeBSD-SA-23:01.geli
Security:	CVE-2023-0751
2023-02-08 10:01:58 -08:00
..
geli.8 geli: Add a chicken switch for unmapped I/O 2022-04-18 17:55:24 -04:00
geom_eli.c geli: split the initalization of HMAC 2023-02-08 10:01:58 -08:00
Makefile pkgbase: Put geom utilities in their own package 2022-10-26 19:46:28 +02:00
Makefile.depend