<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="/source/rss.xsl.xml"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
    <title>Changes in Kconfig</title>
    <description></description>
    <language>en</language>
    <copyright>Copyright 2015</copyright>
    <generator>Java</generator><item>
        <title>c17ee635fd3a482b2ad2bf5e269755c2eae5f25e - Merge drm/drm-fixes into drm-misc-fixes</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#c17ee635fd3a482b2ad2bf5e269755c2eae5f25e</link>
        <description>Merge drm/drm-fixes into drm-misc-fixes7.0-rc1 was just released, let&apos;s merge it to kick the new release cycle.Signed-off-by: Maxime Ripard &lt;mripard@kernel.org&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 23 Feb 2026 10:09:45 +0100</pubDate>
        <dc:creator>Maxime Ripard &lt;mripard@kernel.org&gt;</dc:creator>
    </item>
<item>
        <title>b63c90720348578631cda74285958c3ad3169ce9 - Merge tag &apos;keys-next-20260206&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#b63c90720348578631cda74285958c3ad3169ce9</link>
        <description>Merge tag &apos;keys-next-20260206&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fsPull keys update from David Howells: &quot;This adds support for ML-DSA signatures in X.509 certificates and  PKCS#7/CMS messages, thereby allowing this algorithm to be used for  signing modules, kexec&apos;able binaries, wifi regulatory data, etc..  This requires OpenSSL-3.5 at a minimum and preferably OpenSSL-4 (so  that it can avoid the use of CMS signedAttrs - but that version is not  cut yet). certs/Kconfig does a check to hide the signing options if  OpenSSL does not list the algorithm as being available&quot;* tag &apos;keys-next-20260206&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs:  pkcs7: Change a pr_warn() to pr_warn_once()  pkcs7: Allow authenticatedAttributes for ML-DSA  modsign: Enable ML-DSA module signing  pkcs7, x509: Add ML-DSA support  pkcs7: Allow the signing algo to do whatever digestion it wants itself  pkcs7, x509: Rename -&gt;digest to -&gt;m  x509: Separately calculate sha256 for blacklist  crypto: Add ML-DSA crypto_sig support

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Tue, 10 Feb 2026 18:32:30 +0100</pubDate>
        <dc:creator>Linus Torvalds &lt;torvalds@linux-foundation.org&gt;</dc:creator>
    </item>
<item>
        <title>0ad9a71933e73c8a2af101d28e9a1dc35bae02d5 - modsign: Enable ML-DSA module signing</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#0ad9a71933e73c8a2af101d28e9a1dc35bae02d5</link>
        <description>modsign: Enable ML-DSA module signingAllow ML-DSA module signing to be enabled.Note that OpenSSL&apos;s CMS_*() function suite does not, as of OpenSSL-3.6,support the use of CMS_NOATTR with ML-DSA, so the prohibition against usingsignedAttrs with module signing has to be removed.  The selected digestthen applies only to the algorithm used to calculate the digest stored inthe messageDigest attribute.  The OpenSSL development branch has patchesapplied that fix this[1], but it appears that that will only be availablein OpenSSL-4.[1] https://github.com/openssl/openssl/pull/28923sign-file won&apos;t set CMS_NOATTR if openssl is earlier than v4, resulting inthe use of signed attributes.The ML-DSA algorithm takes the raw data to be signed without regard to whatdigest algorithm is specified in the CMS message.  The CMS specified digestalgorithm is ignored unless signedAttrs are used; in such a case, onlySHA512 is permitted.Signed-off-by: David Howells &lt;dhowells@redhat.com&gt;cc: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;cc: Eric Biggers &lt;ebiggers@kernel.org&gt;cc: Lukas Wunner &lt;lukas@wunner.de&gt;cc: Ignat Korchagin &lt;ignat@cloudflare.com&gt;cc: Stephan Mueller &lt;smueller@chronox.de&gt;cc: Herbert Xu &lt;herbert@gondor.apana.org.au&gt;cc: keyrings@vger.kernel.orgcc: linux-crypto@vger.kernel.org

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 06 Oct 2025 09:35:51 +0200</pubDate>
        <dc:creator>David Howells &lt;dhowells@redhat.com&gt;</dc:creator>
    </item>
<item>
        <title>a23e1966932464e1c5226cb9ac4ce1d5fc10ba22 - Merge branch &apos;next&apos; into for-linus</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#a23e1966932464e1c5226cb9ac4ce1d5fc10ba22</link>
        <description>Merge branch &apos;next&apos; into for-linusPrepare input updates for 6.11 merge window.

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 15 Jul 2024 23:03:44 +0200</pubDate>
        <dc:creator>Dmitry Torokhov &lt;dmitry.torokhov@gmail.com&gt;</dc:creator>
    </item>
<item>
        <title>6f47c7ae8c7afaf9ad291d39f0d3974f191a7946 - Merge tag &apos;v6.9&apos; into next</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#6f47c7ae8c7afaf9ad291d39f0d3974f191a7946</link>
        <description>Merge tag &apos;v6.9&apos; into nextSync up with the mainline to bring in the new cleanup API.

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Tue, 28 May 2024 06:37:18 +0200</pubDate>
        <dc:creator>Dmitry Torokhov &lt;dmitry.torokhov@gmail.com&gt;</dc:creator>
    </item>
<item>
        <title>60a2f25de7b8b785baee2932db932ae9a5b8c86d - Merge drm/drm-next into drm-intel-gt-next</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#60a2f25de7b8b785baee2932db932ae9a5b8c86d</link>
        <description>Merge drm/drm-next into drm-intel-gt-nextSome display refactoring patches are needed in order to allow conflict-less merging.Signed-off-by: Tvrtko Ursulin &lt;tursulin@ursulin.net&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Thu, 16 May 2024 09:33:01 +0200</pubDate>
        <dc:creator>Tvrtko Ursulin &lt;tursulin@ursulin.net&gt;</dc:creator>
    </item>
<item>
        <title>0ea5c948cb64bab5bc7a5516774eb8536f05aa0d - Merge drm/drm-next into drm-intel-next</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#0ea5c948cb64bab5bc7a5516774eb8536f05aa0d</link>
        <description>Merge drm/drm-next into drm-intel-nextBackmerge to bring Xe driver to drm-intel-next.Signed-off-by: Jani Nikula &lt;jani.nikula@intel.com&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 15 Jan 2024 08:38:05 +0100</pubDate>
        <dc:creator>Jani Nikula &lt;jani.nikula@intel.com&gt;</dc:creator>
    </item>
<item>
        <title>03c11eb3b16dc0058589751dfd91f254be2be613 - Merge tag &apos;v6.8-rc4&apos; into x86/percpu, to resolve conflicts and refresh the branch</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#03c11eb3b16dc0058589751dfd91f254be2be613</link>
        <description>Merge tag &apos;v6.8-rc4&apos; into x86/percpu, to resolve conflicts and refresh the branchConflicts:	arch/x86/include/asm/percpu.h	arch/x86/include/asm/text-patching.hSigned-off-by: Ingo Molnar &lt;mingo@kernel.org&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Wed, 14 Feb 2024 10:45:07 +0100</pubDate>
        <dc:creator>Ingo Molnar &lt;mingo@kernel.org&gt;</dc:creator>
    </item>
<item>
        <title>ab1c247094e323177a578b38f0325bf79f0317ac - Merge remote-tracking branch &apos;torvalds/master&apos; into perf-tools-next</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#ab1c247094e323177a578b38f0325bf79f0317ac</link>
        <description>Merge remote-tracking branch &apos;torvalds/master&apos; into perf-tools-nextTo pick up fixes that went thru perf-tools for v6.7 and to get in syncwith upstream to check for drift in the copies of headers, etc.Signed-off-by: Arnaldo Carvalho de Melo &lt;acme@redhat.com&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Tue, 19 Dec 2023 01:37:07 +0100</pubDate>
        <dc:creator>Arnaldo Carvalho de Melo &lt;acme@redhat.com&gt;</dc:creator>
    </item>
<item>
        <title>6b93f350e55f3f2ee071dd41109d936abfba8ebf - Merge branch &apos;for-6.8/amd-sfh&apos; into for-linus</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#6b93f350e55f3f2ee071dd41109d936abfba8ebf</link>
        <description>Merge branch &apos;for-6.8/amd-sfh&apos; into for-linus- addition of new interfaces to export User presence information and  Ambient light from amd-sfh to other drivers within the kernel (Basavaraj  Natikar)

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 08 Jan 2024 20:57:04 +0100</pubDate>
        <dc:creator>Jiri Kosina &lt;jkosina@suse.com&gt;</dc:creator>
    </item>
<item>
        <title>3bf3e21c15d4386a5f15118ec39bbc1b67ea5759 - Merge drm/drm-next into drm-misc-next</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#3bf3e21c15d4386a5f15118ec39bbc1b67ea5759</link>
        <description>Merge drm/drm-next into drm-misc-nextLet&apos;s kickstart the v6.8 release cycle.Signed-off-by: Maxime Ripard &lt;mripard@kernel.org&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Wed, 15 Nov 2023 10:45:19 +0100</pubDate>
        <dc:creator>Maxime Ripard &lt;mripard@kernel.org&gt;</dc:creator>
    </item>
<item>
        <title>5d2d4a9f603a47403395408f64b1261ca61f6d50 - Merge branch &apos;tip/perf/urgent&apos;</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#5d2d4a9f603a47403395408f64b1261ca61f6d50</link>
        <description>Merge branch &apos;tip/perf/urgent&apos;Avoid conflicts, base on fixes.Signed-off-by: Peter Zijlstra &lt;peterz@infradead.org&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Wed, 15 Nov 2023 10:15:40 +0100</pubDate>
        <dc:creator>Peter Zijlstra &lt;peterz@infradead.org&gt;</dc:creator>
    </item>
<item>
        <title>bc3012f4e3a9765de81f454cb8f9bb16aafc6ff5 - Merge tag &apos;v6.7-p1&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#bc3012f4e3a9765de81f454cb8f9bb16aafc6ff5</link>
        <description>Merge tag &apos;v6.7-p1&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6Pull crypto updates from Herbert Xu: &quot;API:   - Add virtual-address based lskcipher interface   - Optimise ahash/shash performance in light of costly indirect calls   - Remove ahash alignmask attribute  Algorithms:   - Improve AES/XTS performance of 6-way unrolling for ppc   - Remove some uses of obsolete algorithms (md4, md5, sha1)   - Add FIPS 202 SHA-3 support in pkcs1pad   - Add fast path for single-page messages in adiantum   - Remove zlib-deflate  Drivers:   - Add support for S4 in meson RNG driver   - Add STM32MP13x support in stm32   - Add hwrng interface support in qcom-rng   - Add support for deflate algorithm in hisilicon/zip&quot;* tag &apos;v6.7-p1&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6: (283 commits)  crypto: adiantum - flush destination page before unmapping  crypto: testmgr - move pkcs1pad(rsa,sha3-*) to correct place  Documentation/module-signing.txt: bring up to date  module: enable automatic module signing with FIPS 202 SHA-3  crypto: asymmetric_keys - allow FIPS 202 SHA-3 signatures  crypto: rsa-pkcs1pad - Add FIPS 202 SHA-3 support  crypto: FIPS 202 SHA-3 register in hash info for IMA  x509: Add OIDs for FIPS 202 SHA-3 hash and signatures  crypto: ahash - optimize performance when wrapping shash  crypto: ahash - check for shash type instead of not ahash type  crypto: hash - move &quot;ahash wrapping shash&quot; functions to ahash.c  crypto: talitos - stop using crypto_ahash::init  crypto: chelsio - stop using crypto_ahash::init  crypto: ahash - improve file comment  crypto: ahash - remove struct ahash_request_priv  crypto: ahash - remove crypto_ahash_alignmask  crypto: gcm - stop using alignmask of ahash  crypto: chacha20poly1305 - stop using alignmask of ahash  crypto: ccm - stop using alignmask of ahash  net: ipv6: stop checking crypto_ahash_alignmask  ...

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Fri, 03 Nov 2023 03:15:30 +0100</pubDate>
        <dc:creator>Linus Torvalds &lt;torvalds@linux-foundation.org&gt;</dc:creator>
    </item>
<item>
        <title>ca219be012786654d5c802ee892433aaa0016d10 - Merge tag &apos;integrity-v6.7&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#ca219be012786654d5c802ee892433aaa0016d10</link>
        <description>Merge tag &apos;integrity-v6.7&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrityPull integrity updates from Mimi Zohar: &quot;Four integrity changes: two IMA-overlay updates, an integrity Kconfig  cleanup, and a secondary keyring update&quot;* tag &apos;integrity-v6.7&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity:  ima: detect changes to the backing overlay file  certs: Only allow certs signed by keys on the builtin keyring  integrity: fix indentation of config attributes  ima: annotate iint mutex to avoid lockdep false positive warnings

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Thu, 02 Nov 2023 17:53:22 +0100</pubDate>
        <dc:creator>Linus Torvalds &lt;torvalds@linux-foundation.org&gt;</dc:creator>
    </item>
<item>
        <title>b46503068cb9ed63ff1d8250f143354ead0b16eb - certs: Only allow certs signed by keys on the builtin keyring</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#b46503068cb9ed63ff1d8250f143354ead0b16eb</link>
        <description>certs: Only allow certs signed by keys on the builtin keyringOriginally the secondary trusted keyring provided a keyring to which extrakeys may be added, provided those keys were not blacklisted and werevouched for by a key built into the kernel or already in the secondarytrusted keyring.On systems with the machine keyring configured, additional keys may alsobe vouched for by a key on the machine keyring.Prevent loading additional certificates directly onto the secondarykeyring, vouched for by keys on the machine keyring, yet allow thesecertificates to be loaded onto other trusted keyrings.Reviewed-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;Signed-off-by: Mimi Zohar &lt;zohar@linux.ibm.com&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 16 Oct 2023 02:18:03 +0200</pubDate>
        <dc:creator>Mimi Zohar &lt;zohar@linux.ibm.com&gt;</dc:creator>
    </item>
<item>
        <title>446b1e0b7b39e2bf2187c58ba2a1cc60fb01de8b - module: enable automatic module signing with FIPS 202 SHA-3</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#446b1e0b7b39e2bf2187c58ba2a1cc60fb01de8b</link>
        <description>module: enable automatic module signing with FIPS 202 SHA-3Add Kconfig options to use SHA-3 for kernel module signing. 256 sizefor RSA only, and higher sizes for RSA and NIST P-384.Signed-off-by: Dimitri John Ledkov &lt;dimitri.ledkov@canonical.com&gt;Signed-off-by: Herbert Xu &lt;herbert@gondor.apana.org.au&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Sun, 22 Oct 2023 20:22:07 +0200</pubDate>
        <dc:creator>Dimitri John Ledkov &lt;dimitri.ledkov@canonical.com&gt;</dc:creator>
    </item>
<item>
        <title>d4f5bfe20da9fa54024a73a9c60aea45e572d786 - certs: Limit MODULE_SIG_KEY_TYPE_ECDSA to SHA384 or SHA512</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#d4f5bfe20da9fa54024a73a9c60aea45e572d786</link>
        <description>certs: Limit MODULE_SIG_KEY_TYPE_ECDSA to SHA384 or SHA512NIST FIPS 186-5 states that it is recommended that the securitystrength associated with the bit length of n and the security strengthof the hash function be the same, or higher upon agreement. Given NISTP384 curve is used, force using either SHA384 or SHA512.Signed-off-by: Dimitri John Ledkov &lt;dimitri.ledkov@canonical.com&gt;Signed-off-by: Herbert Xu &lt;herbert@gondor.apana.org.au&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Tue, 10 Oct 2023 23:27:55 +0200</pubDate>
        <dc:creator>Dimitri John Ledkov &lt;dimitri.ledkov@canonical.com&gt;</dc:creator>
    </item>
<item>
        <title>4f2c0a4acffbec01079c28f839422e64ddeff004 - Merge branch &apos;main&apos; into zstd-linus</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#4f2c0a4acffbec01079c28f839422e64ddeff004</link>
        <description>Merge branch &apos;main&apos; into zstd-linus

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Wed, 14 Dec 2022 01:21:55 +0100</pubDate>
        <dc:creator>Nick Terrell &lt;terrelln@fb.com&gt;</dc:creator>
    </item>
<item>
        <title>e291c116f60f3c1ca98090f0f8e7c77e658562fb - Merge branch &apos;next&apos; into for-linus</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#e291c116f60f3c1ca98090f0f8e7c77e658562fb</link>
        <description>Merge branch &apos;next&apos; into for-linusPrepare input updates for 6.2 merge window.

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 12 Dec 2022 19:47:03 +0100</pubDate>
        <dc:creator>Dmitry Torokhov &lt;dmitry.torokhov@gmail.com&gt;</dc:creator>
    </item>
<item>
        <title>29583dfcd2dd72c766422bd05c16f06c6b1fb356 - Merge drm/drm-next into drm-misc-next-fixes</title>
        <link>http://kernelsources.org:8080/source/history/linux/certs/Kconfig#29583dfcd2dd72c766422bd05c16f06c6b1fb356</link>
        <description>Merge drm/drm-next into drm-misc-next-fixesBackmerging to update drm-misc-next-fixes for the final phaseof the release cycle.Signed-off-by: Thomas Zimmermann &lt;tzimmermann@suse.de&gt;

            List of files:
            /linux/certs/Kconfig</description>
        <pubDate>Mon, 21 Nov 2022 09:03:13 +0100</pubDate>
        <dc:creator>Thomas Zimmermann &lt;tzimmermann@suse.de&gt;</dc:creator>
    </item>
</channel>
</rss>
