This is supported by dropbear since version 2020.79, but was not used by ptxdist yet.
Signed-off-by: Alexander Dahl <[email protected]> --- projectroot/etc/init.d/dropbear | 3 +++ projectroot/etc/rc.once.d/dropbear | 3 +++ projectroot/usr/lib/init/dropbear.sh | 1 + rules/dropbear.in | 12 ++++++++++++ rules/dropbear.make | 11 +++++++++++ 5 files changed, 30 insertions(+) diff --git a/projectroot/etc/init.d/dropbear b/projectroot/etc/init.d/dropbear index 2039340b2..1b16de20a 100644 --- a/projectroot/etc/init.d/dropbear +++ b/projectroot/etc/init.d/dropbear @@ -25,6 +25,9 @@ dropbear_start() { ecdsa) test -f "$DROPBEAR_ECDSAKEY" && KEY_ARGS="$KEY_ARGS -r $DROPBEAR_ECDSAKEY" ;; + ed25519) + test -f "$DROPBEAR_ED25519KEY" && KEY_ARGS="$KEY_ARGS -r $DROPBEAR_ED25519KEY" + ;; *) echo "Key type '$keytype' not supported" ;; diff --git a/projectroot/etc/rc.once.d/dropbear b/projectroot/etc/rc.once.d/dropbear index a8725616a..191f6c61b 100644 --- a/projectroot/etc/rc.once.d/dropbear +++ b/projectroot/etc/rc.once.d/dropbear @@ -28,6 +28,9 @@ gen_keys() { ecdsa) gen_key ecdsa "$DROPBEAR_ECDSAKEY" || return ;; + ed25519) + gen_key ed25519 "$DROPBEAR_ED25519KEY" || return + ;; *) echo "Key type '$keytype' not supported" ;; diff --git a/projectroot/usr/lib/init/dropbear.sh b/projectroot/usr/lib/init/dropbear.sh index 12fd6e5ce..aa375fe3c 100644 --- a/projectroot/usr/lib/init/dropbear.sh +++ b/projectroot/usr/lib/init/dropbear.sh @@ -2,4 +2,5 @@ DROPBEAR_RSAKEY='@KEYDIR@/dropbear_rsa_host_key' DROPBEAR_ECDSAKEY='@KEYDIR@/dropbear_ecdsa_host_key' +DROPBEAR_ED25519KEY='@KEYDIR@/dropbear_ed25519_host_key' DROPBEAR_KEYTYPES='@KEYTYPES@' diff --git a/rules/dropbear.in b/rules/dropbear.in index 553e0268c..a7698ba20 100644 --- a/rules/dropbear.in +++ b/rules/dropbear.in @@ -256,6 +256,18 @@ config DROPBEAR_ECDSA ECDSA stands for Elliptic Curve Digital Signature Algorithm. ECDSA is significantly faster than RSA. +config DROPBEAR_ED25519 + bool + prompt "ed25519" + default y + help + Ed25519 is the EdDSA signature scheme using SHA-512 (SHA-2) + and Curve25519. + Ed25519 is intended to provide attack resistance comparable to + quality 128-bit symmetric ciphers. + Public keys are 256 bits long and signatures are 512 bits + long. + comment "Key exchange algorithm ---" config DROPBEAR_ECDH diff --git a/rules/dropbear.make b/rules/dropbear.make index 3a434e2c8..a5ff02c9e 100644 --- a/rules/dropbear.make +++ b/rules/dropbear.make @@ -202,6 +202,14 @@ else @echo "#define DROPBEAR_ECDSA 0" >> $(DROPBEAR_LOCALOPTIONS) endif +ifdef PTXCONF_DROPBEAR_ED25519 + @echo "ptxdist: enabling ed25519" + @echo "#define DROPBEAR_ED25519 1" >> $(DROPBEAR_LOCALOPTIONS) +else + @echo "ptxdist: disabling ed25519" + @echo "#define DROPBEAR_ED25519 0" >> $(DROPBEAR_LOCALOPTIONS) +endif + @echo "ptxdist: disabling u2f security key support" @echo "#define DROPBEAR_SK_ECDSA 0" >> $(DROPBEAR_LOCALOPTIONS) @echo "#define DROPBEAR_SK_ED25519 0" >> $(DROPBEAR_LOCALOPTIONS) @@ -263,6 +271,9 @@ endif ifdef PTXCONF_DROPBEAR_ECDSA DROPBEAR_KEY_TYPES += ecdsa endif +ifdef PTXCONF_DROPBEAR_ED25519 +DROPBEAR_KEY_TYPES += ed25519 +endif $(STATEDIR)/dropbear.targetinstall: @$(call targetinfo) -- 2.30.2
