We present multiple options in the menu here, so add some more guidance for the non experienced user.
Signed-off-by: Alexander Dahl <[email protected]> --- rules/dropbear.in | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/rules/dropbear.in b/rules/dropbear.in index 375d4c57c..f7f96a762 100644 --- a/rules/dropbear.in +++ b/rules/dropbear.in @@ -149,7 +149,7 @@ config DROPBEAR_AES128 config DROPBEAR_3DES bool - prompt "3DES" + prompt "3DES (legacy)" help DES is an IBM algorithm designed during the 1970s. In 1976, NIST has officially adopted it as an encryption @@ -181,7 +181,7 @@ config DROPBEAR_CHACHA20POLY1305 config DROPBEAR_CBC_CIPHERS bool - prompt "CBC mode ciphers" + prompt "CBC mode ciphers (legacy)" help Enable CBC mode for ciphers. This has security issues though is the most compatible with older SSH implementations. @@ -195,11 +195,11 @@ config DROPBEAR_CTR_CIPHERS CBC mode against certain attacks. This adds around 1kB to binary size and is recommended for most cases. -comment "Integrity, at least one required --- sha2-256 is recommended as a default, sha1 for compatibility" +comment "Message Integrity (HMAC), at least one required ---" config DROPBEAR_SHA1 bool - prompt "sha1" + prompt "sha1 (compat)" help The Secure Hash Algorithm (SHA) was developed by NIST and is specified in the Secure Hash Standard (SHS, FIPS 180). @@ -211,7 +211,7 @@ config DROPBEAR_SHA1 config DROPBEAR_SHA1_96 bool - prompt "sha1-96" + prompt "sha1-96 (legacy)" help The Secure Hash Algorithm (SHA) was developed by NIST and is specified in the Secure Hash Standard (SHS, FIPS 180). @@ -223,7 +223,7 @@ config DROPBEAR_SHA1_96 config DROPBEAR_SHA256 bool - prompt "sha256" + prompt "sha256 (recommended)" default y help SHA-2 is a set of cryptographic hash functions (SHA-224, SHA-256, -- 2.30.2
