EDDSA support yet?

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
10 messages Options
Reply | Threaded
Open this post in threaded view
|

EDDSA support yet?

Robert Moskowitz
My Fedora 28 shipped with:

OpenSSL 1.1.0h-fips  27 Mar 2018

Does that have ED25519 support?

It takes real time to set up my full test environment, and I really
don't have the time right now if I am going to have to see what is in
store for Fedora 29...

Thanks

--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Viktor Dukhovni


> On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <[hidden email]> wrote:
>
> My Fedora 28 shipped with:
>
> OpenSSL 1.1.0h-fips  27 Mar 2018
>
> Does that have ED25519 support?

No.  You'd need 1.1.1 for that, it is currently in beta.

--
        Viktor.

--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Robert Moskowitz


On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:

>
>> On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <[hidden email]> wrote:
>>
>> My Fedora 28 shipped with:
>>
>> OpenSSL 1.1.0h-fips  27 Mar 2018
>>
>> Does that have ED25519 support?
> No.  You'd need 1.1.1 for that, it is currently in beta.
>
No wonder Dr. Google failed me.  I will have to see what I can do.
Perhaps put together a Rawhide system then try for a build.  But that
takes for a time commitment.

thanks


--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Tomas Mraz-2
On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:

>
> On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
> >
> > > On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <[hidden email]
> > > m> wrote:
> > >
> > > My Fedora 28 shipped with:
> > >
> > > OpenSSL 1.1.0h-fips  27 Mar 2018
> > >
> > > Does that have ED25519 support?
> >
> > No.  You'd need 1.1.1 for that, it is currently in beta.
> >
>
> No wonder Dr. Google failed me.  I will have to see what I can do.
> Perhaps put together a Rawhide system then try for a build.  But
> that
> takes for a time commitment.
>

Please note that there is now openssl-1.1.1-pre8 in Rawhide since
yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
release so we will not ship an openssl prerelease in it.

--
Tomáš Mráz
No matter how far down the wrong road you've gone, turn back.
                                              Turkish proverb
[You'll know whether the road is wrong if you carefully listen to your
conscience.]

--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Robert Moskowitz


On 07/26/2018 10:19 AM, Tomas Mraz wrote:

> On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:
>> On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
>>>> On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <[hidden email]
>>>> m> wrote:
>>>>
>>>> My Fedora 28 shipped with:
>>>>
>>>> OpenSSL 1.1.0h-fips  27 Mar 2018
>>>>
>>>> Does that have ED25519 support?
>>> No.  You'd need 1.1.1 for that, it is currently in beta.
>>>
>> No wonder Dr. Google failed me.  I will have to see what I can do.
>> Perhaps put together a Rawhide system then try for a build.  But
>> that
>> takes for a time commitment.
>>
> Please note that there is now openssl-1.1.1-pre8 in Rawhide since
> yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
> release so we will not ship an openssl prerelease in it.
>
Does this include the armv7hl image?  If so, it is not a stretch for me
to build an image on one of my test Cubieboards.


--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

OpenSSL - User mailing list
In reply to this post by Robert Moskowitz
No, you need a 1.1.1 tree.

--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Tomas Mraz-2
In reply to this post by Robert Moskowitz
On Thu, 2018-07-26 at 10:33 -0400, Robert Moskowitz wrote:

>
> On 07/26/2018 10:19 AM, Tomas Mraz wrote:
> > On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:
> > > On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
> > > > > On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <rgm@htt-consul
> > > > > t.co
> > > > > m> wrote:
> > > > >
> > > > > My Fedora 28 shipped with:
> > > > >
> > > > > OpenSSL 1.1.0h-fips  27 Mar 2018
> > > > >
> > > > > Does that have ED25519 support?
> > > >
> > > > No.  You'd need 1.1.1 for that, it is currently in beta.
> > > >
> > >
> > > No wonder Dr. Google failed me.  I will have to see what I can
> > > do.
> > > Perhaps put together a Rawhide system then try for a build.  But
> > > that
> > > takes for a time commitment.
> > >
> >
> > Please note that there is now openssl-1.1.1-pre8 in Rawhide since
> > yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
> > release so we will not ship an openssl prerelease in it.
> >
>
> Does this include the armv7hl image?  If so, it is not a stretch for
> me
> to build an image on one of my test Cubieboards.

Fedora does builds for armv7hl. However I do not see any sufficiently
fresh Rawhide image that would contain this build.

--
Tomáš Mráz
No matter how far down the wrong road you've gone, turn back.
                                              Turkish proverb
[You'll know whether the road is wrong if you carefully listen to your
conscience.]

--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Billy Brumley
Shameless self plug -- OpenSSL engine for 1.0.2, 1.1.0, and later:

https://github.com/romen/libsuola

BBB

On Thu, Jul 26, 2018 at 6:59 PM, Tomas Mraz <[hidden email]> wrote:

> On Thu, 2018-07-26 at 10:33 -0400, Robert Moskowitz wrote:
>>
>> On 07/26/2018 10:19 AM, Tomas Mraz wrote:
>> > On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:
>> > > On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
>> > > > > On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <rgm@htt-consul
>> > > > > t.co
>> > > > > m> wrote:
>> > > > >
>> > > > > My Fedora 28 shipped with:
>> > > > >
>> > > > > OpenSSL 1.1.0h-fips  27 Mar 2018
>> > > > >
>> > > > > Does that have ED25519 support?
>> > > >
>> > > > No.  You'd need 1.1.1 for that, it is currently in beta.
>> > > >
>> > >
>> > > No wonder Dr. Google failed me.  I will have to see what I can
>> > > do.
>> > > Perhaps put together a Rawhide system then try for a build.  But
>> > > that
>> > > takes for a time commitment.
>> > >
>> >
>> > Please note that there is now openssl-1.1.1-pre8 in Rawhide since
>> > yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
>> > release so we will not ship an openssl prerelease in it.
>> >
>>
>> Does this include the armv7hl image?  If so, it is not a stretch for
>> me
>> to build an image on one of my test Cubieboards.
>
> Fedora does builds for armv7hl. However I do not see any sufficiently
> fresh Rawhide image that would contain this build.
>
> --
> Tomáš Mráz
> No matter how far down the wrong road you've gone, turn back.
>                                               Turkish proverb
> [You'll know whether the road is wrong if you carefully listen to your
> conscience.]
>
> --
> openssl-users mailing list
> To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Robert Moskowitz
In reply to this post by Tomas Mraz-2


On 07/26/2018 11:59 AM, Tomas Mraz wrote:

> On Thu, 2018-07-26 at 10:33 -0400, Robert Moskowitz wrote:
>> On 07/26/2018 10:19 AM, Tomas Mraz wrote:
>>> On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:
>>>> On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
>>>>>> On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <rgm@htt-consul
>>>>>> t.co
>>>>>> m> wrote:
>>>>>>
>>>>>> My Fedora 28 shipped with:
>>>>>>
>>>>>> OpenSSL 1.1.0h-fips  27 Mar 2018
>>>>>>
>>>>>> Does that have ED25519 support?
>>>>> No.  You'd need 1.1.1 for that, it is currently in beta.
>>>>>
>>>> No wonder Dr. Google failed me.  I will have to see what I can
>>>> do.
>>>> Perhaps put together a Rawhide system then try for a build.  But
>>>> that
>>>> takes for a time commitment.
>>>>
>>> Please note that there is now openssl-1.1.1-pre8 in Rawhide since
>>> yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
>>> release so we will not ship an openssl prerelease in it.
>>>
>> Does this include the armv7hl image?  If so, it is not a stretch for
>> me
>> to build an image on one of my test Cubieboards.
> Fedora does builds for armv7hl. However I do not see any sufficiently
> fresh Rawhide image that would contain this build.
>
 From the Fedora-arm list:

openssl-1.1.1-0.pre8.fc29 was built and tagged into f29 late yesterday
so it will be in the next successful compose which might be tomorrow
(there's been a few issues), look for the next rawhide report to the
mailing list, else you can just "dnf upgrade" your current f29 image
and you'll get it once it makes the mirrors.


So if is off to power up a cubieboard and get ready to build an image
for testing.




--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users
Reply | Threaded
Open this post in threaded view
|

Re: EDDSA support yet?

Robert Moskowitz
In reply to this post by Tomas Mraz-2


On 07/26/2018 11:59 AM, Tomas Mraz wrote:

> On Thu, 2018-07-26 at 10:33 -0400, Robert Moskowitz wrote:
>> On 07/26/2018 10:19 AM, Tomas Mraz wrote:
>>> On Thu, 2018-07-26 at 10:10 -0400, Robert Moskowitz wrote:
>>>> On 07/26/2018 10:07 AM, Viktor Dukhovni wrote:
>>>>>> On Jul 26, 2018, at 9:01 AM, Robert Moskowitz <rgm@htt-consul
>>>>>> t.co
>>>>>> m> wrote:
>>>>>>
>>>>>> My Fedora 28 shipped with:
>>>>>>
>>>>>> OpenSSL 1.1.0h-fips  27 Mar 2018
>>>>>>
>>>>>> Does that have ED25519 support?
>>>>> No.  You'd need 1.1.1 for that, it is currently in beta.
>>>>>
>>>> No wonder Dr. Google failed me.  I will have to see what I can
>>>> do.
>>>> Perhaps put together a Rawhide system then try for a build.  But
>>>> that
>>>> takes for a time commitment.
>>>>
>>> Please note that there is now openssl-1.1.1-pre8 in Rawhide since
>>> yesterday. Hopefully the TLS-1.3 is final before Fedora 29 final
>>> release so we will not ship an openssl prerelease in it.
>>>
>> Does this include the armv7hl image?  If so, it is not a stretch for
>> me
>> to build an image on one of my test Cubieboards.
> Fedora does builds for armv7hl. However I do not see any sufficiently
> fresh Rawhide image that would contain this build.
>

With:  Fedora-Xfce-armhfp-Rawhide-20180726.n.2-sda.raw.xz

# openssl version
OpenSSL 1.1.1-pre8 (beta) FIPS 20 Jun 2018

So now let's see how making an ED25519 PKI works.


--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users