1 |
On Wed, Sep 22, 2021 at 08:54:40AM -0400, Joshua Kinard wrote: |
2 |
> Is there any advice on how this impacts net-misc/dropbear? That has ECC |
3 |
> (both ECDSA and Ed25519) support, and I use it for SGI/MIPS netboot images. |
4 |
> The build doesn't have any bindist uses in it, and ECC support is a |
5 |
> localoptions.h compile-time option (enabled by default). ECC is much faster |
6 |
> on old SGI hardware and generating the hostkeys at bootup takes just a |
7 |
> second or two, whereas RSA can take up to 10-15 seconds. So I'd like to be |
8 |
> able to use ECC on these platforms and distribute netboot images using them. |
9 |
RedHat doesn't seem to disable ECC in Dropbear: |
10 |
https://src.fedoraproject.org/rpms/dropbear/blob/rawhide/f/dropbear.spec |
11 |
|
12 |
Based on what they've said for OpenSSL, I would expect that they SHOULD |
13 |
have disabled ECC there, but there is certainly no consistency from |
14 |
them. |
15 |
|
16 |
Probably nobody asked legal and just shipped dropbear anyway. |
17 |
|
18 |
If you wanted to stir the pot, you could post to the Fedora legal list |
19 |
and ask for consistency ;-). |
20 |
|
21 |
|
22 |
-- |
23 |
Robin Hugh Johnson |
24 |
Gentoo Linux: Dev, Infra Lead, Foundation Treasurer |
25 |
E-Mail : robbat2@g.o |
26 |
GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85 |
27 |
GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136 |