On Sunday, June 03, 2012 08:55:42 AM Anthony Liguori wrote: > This needs to be optional and disabled by default I think. I strongly > dislike disabling a feature when a user isn't asking for it. You can > introduce a global -enable-fips-mode or something like that.
I'll resend the patch, but before I do I want to make sure the defaults are set to whatever you find acceptable to merging and the second sentence above has me a little confused; do you mean "... dislike _enabling_ a feature when a user isn't asking for it."? -- paul moore security and virtualization @ redhat