Openembedded Core Discussions
 help / color / mirror / Atom feed
* [PATCH] disable medium-strength dropbear ssh ciphers
@ 2018-09-07 19:16 joseph-reynolds
  2018-09-07 20:02 ` ✗ patchtest: failure for " Patchwork
  2018-09-12 12:20 ` [PATCH] " Burton, Ross
  0 siblings, 2 replies; 3+ messages in thread
From: joseph-reynolds @ 2018-09-07 19:16 UTC (permalink / raw)
  To: 'openembedded-core@lists.openembedded.org'

[-- Attachment #1: Type: text/plain, Size: 954 bytes --]

This changes the Dropbear SSH server configuration so it will not
accept medium-strength encryption ciphers including: CBC mode, MD5,
96-bit MAC, and triple DES.

Upstream-Status: Pending

Signed-off-by: Joseph Reynolds 
---
 meta/recipes-core/dropbear/dropbear/localoptions.h | 8 ++++++++
 1 file changed, 8 insertions(+)
 create mode 100644 meta/recipes-core/dropbear/dropbear/localoptions.h

diff --git a/meta/recipes-core/dropbear/dropbear/localoptions.h
b/meta/recipes-core/dropbear/dropbear/localoptions.h
new file mode 100644
index 0000000..ec48c26
--- /dev/null
+++ b/meta/recipes-core/dropbear/dropbear/localoptions.h
@@ -0,0 +1,8 @@
+/* Customize dropbear per default_options.h in the dropbear project
*/
+
+/* Disable insecure ciphers */
+#define DROPBEAR_TWOFISH256 0
+#define DROPBEAR_TWOFISH128 0
+#define DROPBEAR_ENABLE_CBC_MODE 0
+#define DROPBEAR_SHA1_HMAC 0
+#define DROPBEAR_SHA1_96_HMAC 0
-- 
2.7.2



[-- Attachment #2: Type: text/html, Size: 1101 bytes --]

^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-09-12 12:20 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-09-07 19:16 [PATCH] disable medium-strength dropbear ssh ciphers joseph-reynolds
2018-09-07 20:02 ` ✗ patchtest: failure for " Patchwork
2018-09-12 12:20 ` [PATCH] " Burton, Ross

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox