xref: /linux/fs/crypto/Kconfig (revision 67f8bc848ee31831336bd478e57d2f993551902e)
1ec8f24b7SThomas Gleixner# SPDX-License-Identifier: GPL-2.0-only
20b81d077SJaegeuk Kimconfig FS_ENCRYPTION
3643fa961SChandan Rajendra	bool "FS Encryption (Per-file encryption)"
4*5acc6f64SEric Biggers	select BLK_INLINE_ENCRYPTION if BLOCK
5*5acc6f64SEric Biggers	select BLK_INLINE_ENCRYPTION_FALLBACK if BLOCK
60b81d077SJaegeuk Kim	select CRYPTO
7ede7a09fSHerbert Xu	select CRYPTO_SKCIPHER
81546d3feSEric Biggers	select CRYPTO_LIB_AES
9bd0d97b7SEric Biggers	select CRYPTO_LIB_SHA256
1019591f7eSEric Biggers	select CRYPTO_LIB_SHA512
110b81d077SJaegeuk Kim	select KEYS
120b81d077SJaegeuk Kim	help
130b81d077SJaegeuk Kim	  Enable encryption of files and directories.  This
140b81d077SJaegeuk Kim	  feature is similar to ecryptfs, but it is more memory
150b81d077SJaegeuk Kim	  efficient since it avoids caching the encrypted and
16643fa961SChandan Rajendra	  decrypted pages in the page cache.  Currently Ext4,
17c1f1f5bfSEric Biggers	  F2FS, UBIFS, and CephFS make use of this feature.
18ede7a09fSHerbert Xu
19ede7a09fSHerbert Xu# Filesystems supporting encryption must select this if FS_ENCRYPTION.  This
20a0fc2033SArd Biesheuvel# allows the algorithms to be built as modules when all the filesystems are,
21a0fc2033SArd Biesheuvel# whereas selecting them from FS_ENCRYPTION would force them to be built-in.
22a0fc2033SArd Biesheuvel#
23a0fc2033SArd Biesheuvel# Note: this option only pulls in the algorithms that filesystem encryption
24a0fc2033SArd Biesheuvel# needs "by default".  If userspace will use "non-default" encryption modes such
25a0fc2033SArd Biesheuvel# as Adiantum encryption, then those other modes need to be explicitly enabled
26a0fc2033SArd Biesheuvel# in the crypto API; see Documentation/filesystems/fscrypt.rst for details.
27a0fc2033SArd Biesheuvel#
28a0fc2033SArd Biesheuvel# Also note that this option only pulls in the generic implementations of the
29a0fc2033SArd Biesheuvel# algorithms, not any per-architecture optimized implementations.  It is
3075eb8b94SEric Biggers# strongly recommended to enable optimized implementations too.
31ede7a09fSHerbert Xuconfig FS_ENCRYPTION_ALGS
32ede7a09fSHerbert Xu	tristate
3375eb8b94SEric Biggers	select CRYPTO_AES
3475eb8b94SEric Biggers	select CRYPTO_CBC
3575eb8b94SEric Biggers	select CRYPTO_CTS
3675eb8b94SEric Biggers	select CRYPTO_XTS
375fee3609SSatya Tangirala
385fee3609SSatya Tangiralaconfig FS_ENCRYPTION_INLINE_CRYPT
39*5acc6f64SEric Biggers	bool
40*5acc6f64SEric Biggers	default y if FS_ENCRYPTION && BLOCK
41