We have multiple groups where it is required to select at least one (and
optionally more) option.  On some groups selecting no option would fail
at buildtime, on other dropbear would build and run, but necessary user
interactions (like log in) would not be possible at runtime, e.g.
because no message integrity hmac method was built in.

These warnings still allow not selecting any option, but should give a
stronger hint than before, that this would be a bad idea.

Suggested-by: Ahmad Fatoum <[email protected]>
Signed-off-by: Alexander Dahl <[email protected]>
---
 rules/dropbear.in | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/rules/dropbear.in b/rules/dropbear.in
index 043b0e76d..4f6a6a906 100644
--- a/rules/dropbear.in
+++ b/rules/dropbear.in
@@ -179,6 +179,9 @@ config DROPBEAR_CHACHA20POLY1305
          instructions, having the same key size.
          Recommended.
 
+comment "WARNING: No encryption method selected!"
+       depends on !DROPBEAR_AES128 && !DROPBEAR_3DES && !DROPBEAR_AES256 && 
!DROPBEAR_CHACHA20POLY1305
+
 config DROPBEAR_CBC_CIPHERS
        bool
        prompt "CBC mode ciphers (legacy)"
@@ -247,6 +250,9 @@ config DROPBEAR_SHA512
          SHA-1. SHA-2 consists of a set of four hash functions with digests
          that are 224, 256, 384 or 512 bits.
 
+comment "WARNING: No Message Integrity method selected!"
+       depends on !DROPBEAR_SHA1 && !DROPBEAR_SHA1_96 && !DROPBEAR_SHA256 && 
!DROPBEAR_SHA512
+
 comment "Hostkey/public key algorithms, at least one required ---"
 
 config DROPBEAR_RSA
@@ -278,6 +284,9 @@ config DROPBEAR_ED25519
          Public keys are 256 bits long and signatures are 512 bits
          long.
 
+comment "WARNING: No Hostkey/public key algorithm selected!"
+       depends on !DROPBEAR_RSA && !DROPBEAR_ECDSA && !DROPBEAR_ED25519
+
 comment "Key exchange algorithm, at least one required ---"
 
 config DROPBEAR_DH_GROUP14_SHA256
@@ -335,6 +344,9 @@ config DROPBEAR_DH_GROUP1
          versions < 0.53.
          Client only!
 
+comment "WARNING: No key exchange algorithm selected!"
+       depends on !DROPBEAR_DH_GROUP14_SHA256 && !DROPBEAR_DH_GROUP14_SHA1 && 
!DROPBEAR_DH_GROUP16 && !DROPBEAR_ECDH && !DROPBEAR_CURVE25519 && 
!DROPBEAR_DH_GROUP1
+
 comment "Authentication types, at least one required --- RFC Draft requires 
pubkey auth"
 
 config DROPBEAR_PASSWD
@@ -351,6 +363,9 @@ config DROPBEAR_PUBKEY
        help
          Use public key authentication
 
+comment "WARNING: No authentication type selected!"
+       depends on !DROPBEAR_PASSWD && !DROPBEAR_PUBKEY
+
 comment "installation options   ---"
 
 config DROPBEAR_DROPBEAR
-- 
2.30.2


Reply via email to