On Sat, Sep 05, 2026 at 12:26:37AM +0200, Alexander Bluhm wrote:
> Hi,
> 
> security/p5-Crypt-DSA is deprecated and recommends to use Crypt-DSA-GMP
> instead.

The cryptographic primitive DSA itself should be considered deprecated
and nobody should recommend its use anymore. For example, FIPS 186-5
deprecated it in 2023 and OpenSSH did so a decade ago and completely
removed support a while back.

This module has last seen a release thirteen years ago and is based on
GMP, which is a dubious choice for cryptography.

Then again DSA is among the more appealing and modern dependecies of
p5-Crypt-OpenPGP.

> So let's port p5-Crypt-DSA-GMP.  Note that its dependency
> Crypt::Random::Seed has not been ported and has multiple weak random
> sources for Windows and Linux.  Better replace it with Unix::OpenBSD::Random
> which uses our libc arc4random(3).
> 
> ok to import p5-Crypt-DSA 0.02 ?

I'm really not keen on adding p5-Crypt-DSA-GMP. Why do we need it? Do
you plan on replacing the p5-Crypt-DSA dep of p5-Crypt-OpenPGP? This
then makes me wonder why we need that.

Ports-wise it looks fine. A few tests only run if p5-Convert-PEM is
installed, so I think it should be at least a test dependency. Adding
it as an rdep would also make sense to me.

Reply via email to