The options for diffie-hellman key exchange were mixed up with message integrity hmacs.
Signed-off-by: Alexander Dahl <[email protected]> --- rules/dropbear.in | 43 +++++++++++++++++++++++++++++++++++++++++-- rules/dropbear.make | 36 ++++++++++++++++++++++++++++++++---- 2 files changed, 73 insertions(+), 6 deletions(-) diff --git a/rules/dropbear.in b/rules/dropbear.in index f7f96a762..043b0e76d 100644 --- a/rules/dropbear.in +++ b/rules/dropbear.in @@ -278,23 +278,62 @@ config DROPBEAR_ED25519 Public keys are 256 bits long and signatures are 512 bits long. -comment "Key exchange algorithm ---" +comment "Key exchange algorithm, at least one required ---" + +config DROPBEAR_DH_GROUP14_SHA256 + bool + prompt "group14_sha256" + default y + help + 2048 bit, sha2-256. + group14 is supported by most implementations. + +config DROPBEAR_DH_GROUP14_SHA1 + bool + prompt "group14_sha1" + help + 2048 bit, sha1. + group14 is supported by most implementations. + +config DROPBEAR_DH_GROUP16 + bool + prompt "group16" + help + 4096 bit, sha2-512. + group16 provides a greater strength level but is slower and + increases binary size. config DROPBEAR_ECDH bool prompt "ecdh" help ECDH stands for Elliptic Curve Diffie-Hellman. + + Small systems should generally include either curve25519 or + ecdh for performance. config DROPBEAR_CURVE25519 bool - prompt "curve25519-donna" + prompt "curve25519" help Enable curve25519-donna for key exchange. This is another elliptic curve method with good security properties. This algorithm does not rely on NIST-based curves and gives us more security confidence against a possible backdoor in nistp-256 curve. + + Small systems should generally include either curve25519 or + ecdh for performance. + +config DROPBEAR_DH_GROUP1 + bool + prompt "group1 (legacy, client only)" + help + 1024 bit, sha1. + is too small for security though is necessary if you need + compatibility with some implementations such as Dropbear + versions < 0.53. + Client only! comment "Authentication types, at least one required --- RFC Draft requires pubkey auth" diff --git a/rules/dropbear.make b/rules/dropbear.make index 7653cf3e5..e86b8bf43 100644 --- a/rules/dropbear.make +++ b/rules/dropbear.make @@ -157,13 +157,9 @@ endif ifdef PTXCONF_DROPBEAR_SHA1 @echo "ptxdist: enabling sha1" @echo "#define DROPBEAR_SHA1_HMAC 1" >> $(DROPBEAR_LOCALOPTIONS) - @echo "#define DROPBEAR_DH_GROUP1 1" >> $(DROPBEAR_LOCALOPTIONS) - @echo "#define DROPBEAR_DH_GROUP14_SHA1 1" >> $(DROPBEAR_LOCALOPTIONS) else @echo "ptxdist: disabling sha1" @echo "#define DROPBEAR_SHA1_HMAC 0" >> $(DROPBEAR_LOCALOPTIONS) - @echo "#define DROPBEAR_DH_GROUP1 0" >> $(DROPBEAR_LOCALOPTIONS) - @echo "#define DROPBEAR_DH_GROUP14_SHA1 0" >> $(DROPBEAR_LOCALOPTIONS) endif ifdef PTXCONF_DROPBEAR_SHA1_96 @@ -223,6 +219,30 @@ endif @echo "#define DROPBEAR_SK_ED25519 0" >> $(DROPBEAR_LOCALOPTIONS) # key exchange algorithm +ifdef PTXCONF_DROPBEAR_DH_GROUP14_SHA256 + @echo "ptxdist: enabling dh_group14_sha256" + @echo "#define DROPBEAR_DH_GROUP14_SHA256 1" >> $(DROPBEAR_LOCALOPTIONS) +else + @echo "ptxdist: disabling dh_group14_sha256" + @echo "#define DROPBEAR_DH_GROUP14_SHA256 0" >> $(DROPBEAR_LOCALOPTIONS) +endif + +ifdef PTXCONF_DROPBEAR_DH_GROUP14_SHA1 + @echo "ptxdist: enabling dh_group14_sha1" + @echo "#define DROPBEAR_DH_GROUP14_SHA1 1" >> $(DROPBEAR_LOCALOPTIONS) +else + @echo "ptxdist: disabling dh_group14_sha1" + @echo "#define DROPBEAR_DH_GROUP14_SHA1 0" >> $(DROPBEAR_LOCALOPTIONS) +endif + +ifdef PTXCONF_DROPBEAR_DH_GROUP16 + @echo "ptxdist: enabling dh_group16" + @echo "#define DROPBEAR_DH_GROUP16 1" >> $(DROPBEAR_LOCALOPTIONS) +else + @echo "ptxdist: disabling dh_group16" + @echo "#define DROPBEAR_DH_GROUP16 0" >> $(DROPBEAR_LOCALOPTIONS) +endif + ifdef PTXCONF_DROPBEAR_ECDH @echo "ptxdist: enabling ecdh" @echo "#define DROPBEAR_ECDH 1" >> $(DROPBEAR_LOCALOPTIONS) @@ -239,6 +259,14 @@ else @echo "#define DROPBEAR_CURVE25519 0" >> $(DROPBEAR_LOCALOPTIONS) endif +ifdef PTXCONF_DROPBEAR_DH_GROUP1 + @echo "ptxdist: enabling dh_group1" + @echo "#define DROPBEAR_DH_GROUP1 1" >> $(DROPBEAR_LOCALOPTIONS) +else + @echo "ptxdist: disabling dh_group1" + @echo "#define DROPBEAR_DH_GROUP1 0" >> $(DROPBEAR_LOCALOPTIONS) +endif + # authentication types ifdef PTXCONF_DROPBEAR_PASSWD @echo "ptxdist: enabling passwd" -- 2.30.2
