Noteworthy pieces from a longer list of changes and fixes:

- New server support for U2F/FIDO keys (explicitly disabled for now)
- Removed Twofish cipher
- Dropbear now re-executes itself rather than just forking for each connection
- A missing home directory is now non-fatal, starting in / instead

Link: https://matt.ucc.asn.au/dropbear/CHANGES
Signed-off-by: Alexander Dahl <[email protected]>
---
 rules/dropbear.in   | 23 -----------------------
 rules/dropbear.make | 25 +++++++------------------
 2 files changed, 7 insertions(+), 41 deletions(-)

diff --git a/rules/dropbear.in b/rules/dropbear.in
index 8ae2d788b..553e0268c 100644
--- a/rules/dropbear.in
+++ b/rules/dropbear.in
@@ -169,29 +169,6 @@ config DROPBEAR_AES256
          algorithm that may be used by U.S. Government organizations
          (and others) to protect sensitive information.
 
-
-config DROPBEAR_TWOFISH128
-       bool
-       prompt "Twofish128"
-       help
-         Another great algorithm designed by Bruce Schneier.
-         This block cipher was designed as a successor to
-         the 64-bit Blowfish block cipher.
-         Twofish combines a 16-round Feistel network with a
-         bijective f function made by four key-dependent
-         8x8-bit S-boxes.
-
-config DROPBEAR_TWOFISH256
-       bool
-       prompt "Twofish256"
-       help
-         Another great algorithm designed by Bruce Schneier.
-         This block cipher was designed as a successor to
-         the 64-bit Blowfish block cipher.
-         Twofish combines a 16-round Feistel network with a
-         bijective f function made by four key-dependent
-         8x8-bit S-boxes.
-
 config DROPBEAR_CBC_CIPHERS
        bool
        prompt "CBC mode ciphers"
diff --git a/rules/dropbear.make b/rules/dropbear.make
index cb949d761..3a434e2c8 100644
--- a/rules/dropbear.make
+++ b/rules/dropbear.make
@@ -16,8 +16,8 @@ PACKAGES-$(PTXCONF_DROPBEAR) += dropbear
 #
 # Paths and names
 #
-DROPBEAR_VERSION       := 2020.81
-DROPBEAR_MD5           := a07438a6159a24c61f98f1bce2d479c0
+DROPBEAR_VERSION       := 2022.82
+DROPBEAR_MD5           := 7a4a5f2c6d23ff2e6627c97d7c1aeceb
 DROPBEAR               := dropbear-$(DROPBEAR_VERSION)
 DROPBEAR_SUFFIX                := tar.bz2
 DROPBEAR_URL           := 
https://matt.ucc.asn.au/dropbear/releases/$(DROPBEAR).$(DROPBEAR_SUFFIX)
@@ -42,6 +42,7 @@ DROPBEAR_CONF_TOOL    := autoconf
 DROPBEAR_CONF_OPT      := \
        $(CROSS_AUTOCONF_USR) \
        --enable-harden \
+       --disable-werror \
        $(GLOBAL_LARGE_FILE_OPTION) \
        --$(call ptx/endis, PTXCONF_DROPBEAR_ZLIB)-zlib \
        --disable-pam \
@@ -126,22 +127,6 @@ else
        @echo "#define DROPBEAR_AES256 0" >> $(DROPBEAR_LOCALOPTIONS)
 endif
 
-ifdef PTXCONF_DROPBEAR_TWOFISH256
-       @echo "ptxdist: enabling twofish256"
-       @echo "#define DROPBEAR_TWOFISH256 1" >> $(DROPBEAR_LOCALOPTIONS)
-else
-       @echo "ptxdist: disabling twofish256"
-       @echo "#define DROPBEAR_TWOFISH256 0" >> $(DROPBEAR_LOCALOPTIONS)
-endif
-
-ifdef PTXCONF_DROPBEAR_TWOFISH128
-       @echo "ptxdist: enabling twofish128"
-       @echo "#define DROPBEAR_TWOFISH128 1" >> $(DROPBEAR_LOCALOPTIONS)
-else
-       @echo "ptxdist: disabling twofish128"
-       @echo "#define DROPBEAR_TWOFISH128 0" >> $(DROPBEAR_LOCALOPTIONS)
-endif
-
 # ciphers
 ifdef PTXCONF_DROPBEAR_CBC_CIPHERS
        @echo "ptxdist: enabling cbc ciphers"
@@ -217,6 +202,10 @@ else
        @echo "#define DROPBEAR_ECDSA 0" >> $(DROPBEAR_LOCALOPTIONS)
 endif
 
+       @echo "ptxdist: disabling u2f security key support"
+       @echo "#define DROPBEAR_SK_ECDSA 0" >> $(DROPBEAR_LOCALOPTIONS)
+       @echo "#define DROPBEAR_SK_ED25519 0" >> $(DROPBEAR_LOCALOPTIONS)
+
 # key exchange algorithm
 ifdef PTXCONF_DROPBEAR_ECDH
        @echo "ptxdist: enabling ecdh"
-- 
2.30.2


Reply via email to