mirror of
https://github.com/clearml/dropbear
synced 2025-03-03 10:41:39 +00:00
move group14 and group16 to options.h, group14-sha256 on by default
This commit is contained in:
parent
8174300429
commit
4664ce2c35
14
options.h
14
options.h
@ -168,10 +168,20 @@ If you test it please contact the Dropbear author */
|
||||
* ECDSA above */
|
||||
#define DROPBEAR_ECDH
|
||||
|
||||
/* Group14 (2048 bit) is recommended. Group1 is less secure (1024 bit) though
|
||||
is the only option for interoperability with some older SSH programs */
|
||||
/* Key exchange algorithm.
|
||||
* group1 - 1024 bit, sha1
|
||||
* group14 - 2048 bit, sha1
|
||||
* group14_256 - 2048 bit, sha2-256
|
||||
* group16 - 4096 bit, sha2-512
|
||||
*
|
||||
* group14 is supported by most implementations.
|
||||
* group16 provides a greater strength but is slower and increases binary size
|
||||
* group1 is necessary if compatibility with Dropbear versions < 0.53 is required
|
||||
*/
|
||||
#define DROPBEAR_DH_GROUP1 1
|
||||
#define DROPBEAR_DH_GROUP14 1
|
||||
#define DROPBEAR_DH_GROUP14_256 1
|
||||
#define DROPBEAR_DH_GROUP16 0
|
||||
|
||||
/* Control the memory/performance/compression tradeoff for zlib.
|
||||
* Set windowBits=8 for least memory usage, see your system's
|
||||
|
@ -127,11 +127,6 @@
|
||||
#define DROPBEAR_MD5
|
||||
#endif
|
||||
|
||||
/* These are disabled in Dropbear 2016.73 by default since the spec
|
||||
draft-ietf-curdle-ssh-kex-sha2-02 is under development. */
|
||||
#define DROPBEAR_DH_GROUP14_256 0
|
||||
#define DROPBEAR_DH_GROUP16 0
|
||||
|
||||
/* roughly 2x 521 bits */
|
||||
#define MAX_ECC_SIZE 140
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user