On 04/07/2022 13:18, Alexander Dahl wrote:
The options for diffie-hellman key exchange were mixed up with message
integrity hmacs.
Signed-off-by: Alexander Dahl <[email protected]>
---
rules/dropbear.in | 43 +++++++++++++++++++++++++++++++++++++++++--
rules/dropbear.make | 36 ++++++++++++++++++++++++++++++++----
2 files changed, 73 insertions(+), 6 deletions(-)
diff --git a/rules/dropbear.in b/rules/dropbear.in
index f7f96a762..043b0e76d 100644
--- a/rules/dropbear.in
+++ b/rules/dropbear.in
[snip]
config DROPBEAR_CURVE25519
bool
- prompt "curve25519-donna"
+ prompt "curve25519"
help
Enable curve25519-donna for key exchange.
The name in the prompt now differs from the name in the help text, which
might be confusing.
This is another elliptic curve method with good security properties.
This algorithm does not rely on NIST-based curves
and gives us more security confidence against a possible
backdoor in nistp-256 curve.
+
+ Small systems should generally include either curve25519 or
+ ecdh for performance.
+
+config DROPBEAR_DH_GROUP1
+ bool
+ prompt "group1 (legacy, client only)"
+ help
+ 1024 bit, sha1.
+ is too small for security though is necessary if you need
+ compatibility with some implementations such as Dropbear
+ versions < 0.53.
+ Client only!
Missing word "This"?
--
-=( Ian Abbott <[email protected]> || MEV Ltd. is a company )=-
-=( registered in England & Wales. Regd. number: 02862268. )=-
-=( Regd. addr.: S11 & 12 Building 67, Europa Business Park, )=-
-=( Bird Hall Lane, STOCKPORT, SK3 0XA, UK. || www.mev.co.uk )=-