aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorHauke Mehrtens <hauke@hauke-m.de>2023-11-05 23:05:24 +0100
committerHauke Mehrtens <hauke@hauke-m.de>2023-11-07 00:37:20 +0100
commit3223f31fd384c938c1a5aa01fb496cec64498704 (patch)
tree5655ddc138a283829f5ed3a6040a73c6ea27c548
parentcfadbc090c3f2f886eecb20b0272a32de4b74194 (diff)
downloadupstream-3223f31fd384c938c1a5aa01fb496cec64498704.tar.gz
upstream-3223f31fd384c938c1a5aa01fb496cec64498704.tar.bz2
upstream-3223f31fd384c938c1a5aa01fb496cec64498704.zip
mbedtls: Activate secp521r1 curve by default
Activate the secp521r1 ecliptic curve by default. This curve is allowed by the CA/Browser forum, see https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-v2.0.1-redlined.pdf#page=110 This increases the size of libmbedtls12_2.28.5-1_aarch64_generic.ipk by about 400 bytes: Without: 252,696 libmbedtls12_2.28.5-1_aarch64_generic.ipk With: 253,088 libmbedtls12_2.28.5-2_aarch64_generic.ipk Fixes: #13774 Acked-by: Koen Vandeputte <koen.vandeputte@citymesh.com> Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de> (cherry picked from commit 3c17cdbc369d89ff6a7911c3acff2e493778f6c1)
-rw-r--r--package/libs/mbedtls/Config.in2
-rw-r--r--package/libs/mbedtls/Makefile2
2 files changed, 2 insertions, 2 deletions
diff --git a/package/libs/mbedtls/Config.in b/package/libs/mbedtls/Config.in
index ffabd799d3..9fbe9f8a4a 100644
--- a/package/libs/mbedtls/Config.in
+++ b/package/libs/mbedtls/Config.in
@@ -104,7 +104,7 @@ config MBEDTLS_ECP_DP_SECP384R1_ENABLED
config MBEDTLS_ECP_DP_SECP521R1_ENABLED
bool "MBEDTLS_ECP_DP_SECP521R1_ENABLED"
- default n
+ default y
config MBEDTLS_ECP_DP_SECP192K1_ENABLED
bool "MBEDTLS_ECP_DP_SECP192K1_ENABLED"
diff --git a/package/libs/mbedtls/Makefile b/package/libs/mbedtls/Makefile
index 6f0b5162eb..246b21a853 100644
--- a/package/libs/mbedtls/Makefile
+++ b/package/libs/mbedtls/Makefile
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=mbedtls
PKG_VERSION:=2.28.5
-PKG_RELEASE:=1
+PKG_RELEASE:=2
PKG_BUILD_FLAGS:=no-mips16 gc-sections no-lto
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz