diff options
author | Herbert Xu <herbert@gondor.apana.org.au> | 2007-10-08 20:14:34 -0400 |
---|---|---|
committer | David S. Miller <davem@sunset.davemloft.net> | 2007-10-10 19:54:53 -0400 |
commit | bc31d3b2c7d7f2a03721a05cb3c9a3ce8b1e2e5a (patch) | |
tree | 4e72919c351590c8276534e797eae8260d20f28c /net/ipv6/ah6.c | |
parent | 4b7137ff8fb49d7bf22dfa248baa0d02ace2c43d (diff) |
[IPSEC] ah: Remove keys from ah_data structure
The keys are only used during initialisation so we don't need to carry them
in esp_data. Since we don't have to allocate them again, there is no need
to place a limit on the authentication key length anymore.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv6/ah6.c')
-rw-r--r-- | net/ipv6/ah6.c | 9 |
1 files changed, 2 insertions, 7 deletions
diff --git a/net/ipv6/ah6.c b/net/ipv6/ah6.c index 53f46ab6af70..69a2030407b8 100644 --- a/net/ipv6/ah6.c +++ b/net/ipv6/ah6.c | |||
@@ -429,10 +429,6 @@ static int ah6_init_state(struct xfrm_state *x) | |||
429 | if (!x->aalg) | 429 | if (!x->aalg) |
430 | goto error; | 430 | goto error; |
431 | 431 | ||
432 | /* null auth can use a zero length key */ | ||
433 | if (x->aalg->alg_key_len > 512) | ||
434 | goto error; | ||
435 | |||
436 | if (x->encap) | 432 | if (x->encap) |
437 | goto error; | 433 | goto error; |
438 | 434 | ||
@@ -440,14 +436,13 @@ static int ah6_init_state(struct xfrm_state *x) | |||
440 | if (ahp == NULL) | 436 | if (ahp == NULL) |
441 | return -ENOMEM; | 437 | return -ENOMEM; |
442 | 438 | ||
443 | ahp->key = x->aalg->alg_key; | ||
444 | ahp->key_len = (x->aalg->alg_key_len+7)/8; | ||
445 | tfm = crypto_alloc_hash(x->aalg->alg_name, 0, CRYPTO_ALG_ASYNC); | 439 | tfm = crypto_alloc_hash(x->aalg->alg_name, 0, CRYPTO_ALG_ASYNC); |
446 | if (IS_ERR(tfm)) | 440 | if (IS_ERR(tfm)) |
447 | goto error; | 441 | goto error; |
448 | 442 | ||
449 | ahp->tfm = tfm; | 443 | ahp->tfm = tfm; |
450 | if (crypto_hash_setkey(tfm, ahp->key, ahp->key_len)) | 444 | if (crypto_hash_setkey(tfm, x->aalg->alg_key, |
445 | (x->aalg->alg_key_len + 7) / 8)) | ||
451 | goto error; | 446 | goto error; |
452 | 447 | ||
453 | /* | 448 | /* |