diff options
author | Eneas U de Queiroz <cote2004-github@yahoo.com> | 2019-03-12 13:16:01 +0000 |
---|---|---|
committer | Hans Dedecker <dedeckeh@gmail.com> | 2019-03-12 18:26:59 +0100 |
commit | 2407b1edccc2f2d426333bd7cc1743c8e4da8dbd (patch) | |
tree | be00dce1b17d00abe03b423582c1a8d649dfad7f /package/libs/openssl/Config.in | |
parent | 8c593804d078f62de981ee0ff05d666b0d1f4df0 (diff) | |
download | upstream-2407b1edccc2f2d426333bd7cc1743c8e4da8dbd.tar.gz upstream-2407b1edccc2f2d426333bd7cc1743c8e4da8dbd.tar.bz2 upstream-2407b1edccc2f2d426333bd7cc1743c8e4da8dbd.zip |
openssl: disable digests by default, misc fixes
Openssh uses digest contexts across forks, which is not supported by the
/dev/crypto engine. The speed of digests is usually not worth enabling
them anyway. This changes the default of the DIGESTS option to NONE, so
the user still has the option to enable them.
Added another patch related to the use of encryption contexts across
forks, that ignores a failure to close a previous open session when
reinitializing a context, instead of failing the reinitialization.
Added a link to the Cryptographic Hardware Accelerators document to the
engine pacakges description, to provide more detailed instructions to
configure the engines.
Revert the removal of the OPENSSL_ENGINE_CRYPTO symbol, currently used
by openssh. There is an open PR to update openssh; when merged, this
symbol can be safely removed.
Signed-off-by: Eneas U de Queiroz <cote2004-github@yahoo.com>
Signed-off-by: Hans Dedecker <dedeckeh@gmail.com> [refresh patches]
Diffstat (limited to 'package/libs/openssl/Config.in')
-rw-r--r-- | package/libs/openssl/Config.in | 11 |
1 files changed, 10 insertions, 1 deletions
diff --git a/package/libs/openssl/Config.in b/package/libs/openssl/Config.in index 235f38e787..ecb9eea389 100644 --- a/package/libs/openssl/Config.in +++ b/package/libs/openssl/Config.in @@ -269,7 +269,13 @@ config OPENSSL_ENGINE_BUILTIN_AFALG select PACKAGE_libopenssl-conf help This enables use of hardware acceleration through the - AF_ALG kenrel interface. + AF_ALG kernel interface. + +config OPENSSL_ENGINE_CRYPTO + # This symbol is deprecated. Currently it is used by the openssh package. + # Once openwrt/packages#8272 is merged, this can be safely removed. + bool + default OPENSSL_ENGINE_BUILTIN_DEVCRYPTO || PACKAGE_libopenssl-devcrypto config OPENSSL_ENGINE_BUILTIN_DEVCRYPTO bool @@ -279,6 +285,9 @@ config OPENSSL_ENGINE_BUILTIN_DEVCRYPTO help This enables use of hardware acceleration through OpenBSD Cryptodev API (/dev/crypto) interface. + Even though configuration is not strictly needed, it is worth seeing + https://openwrt.org/docs/techref/hardware/cryptographic.hardware.accelerators + for information on how to configure the engine. config OPENSSL_ENGINE_BUILTIN_PADLOCK bool |