View previous topic :: View next topic |
Author |
Message |
toralf Developer
data:image/s3,"s3://crabby-images/783ea/783eacf9cb279246e35870bf72711a7ea59f11c1" alt="Developer Developer"
data:image/s3,"s3://crabby-images/7b492/7b4927980d8472dbcc74488b17b964a9a5209e3d" alt=""
Joined: 01 Feb 2004 Posts: 3943 Location: Hamburg
|
Posted: Thu Jan 01, 2015 3:27 pm Post subject: [solved] How do I build opensl with NIST P-224 and P-256 ? |
|
|
read this in the tor log : Code: | Jan 01 15:13:18.000 [notice] We were built to run on a 64-bit CPU, with OpenSSL 1.0.1 or later, but with a version of OpenSSL that apparently lacks accelerated support for the NIST P-224 and P-256 groups. Building openssl with such support (using the enable-ec_nistp_64_gcc_128 option when configuring it) would make ECDH much faster.
|
Last edited by toralf on Fri Jan 02, 2015 7:08 pm; edited 1 time in total |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
khayyam Watchman
data:image/s3,"s3://crabby-images/83d8c/83d8cba7c4ce9429a5365569fadde78b4cf5b30d" alt="Watchman Watchman"
data:image/s3,"s3://crabby-images/a4cfb/a4cfbf2f1f736fa276bfb06620cab594335248af" alt=""
Joined: 07 Jun 2012 Posts: 6227 Location: Room 101
|
Posted: Fri Jan 02, 2015 1:41 pm Post subject: Re: How do I build opensl with NIST P-224 and P-256 ? |
|
|
toralf ... you could try using package.env (untested)
/etc/portage/env/openssl.conf
Code: | EXTRA_ECONF="enable-ec_nistp_64_gcc_128" |
/etc/portage/package.env
Code: | dev-libs/openssl openssl.conf |
HTH & best ... khay |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
toralf Developer
data:image/s3,"s3://crabby-images/783ea/783eacf9cb279246e35870bf72711a7ea59f11c1" alt="Developer Developer"
data:image/s3,"s3://crabby-images/7b492/7b4927980d8472dbcc74488b17b964a9a5209e3d" alt=""
Joined: 01 Feb 2004 Posts: 3943 Location: Hamburg
|
Posted: Fri Jan 02, 2015 6:12 pm Post subject: |
|
|
Hhm, won't work : Code: | $> grep nist /etc/portage/package.env
dev-libs/openssl test ssl_nist
$> cat /etc/portage/env/ssl_nist
EXTRA_ECONF="enable-ec_nistp_64_gcc_128"
$> zgrep nistp.64 *openssl* *openssl*2015*
dev-libs:openssl-1.0.1j:20150102-135319.log.gz: no-ec_nistp_64_gcc_128 [default] OPENSSL_NO_EC_NISTP_64_GCC_128 (skip dir)
|
data:image/s3,"s3://crabby-images/773c4/773c44563c76c6b2b9ae00a1e1bee12096855a27" alt="Sad :-(" |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
khayyam Watchman
data:image/s3,"s3://crabby-images/83d8c/83d8cba7c4ce9429a5365569fadde78b4cf5b30d" alt="Watchman Watchman"
data:image/s3,"s3://crabby-images/a4cfb/a4cfbf2f1f736fa276bfb06620cab594335248af" alt=""
Joined: 07 Jun 2012 Posts: 6227 Location: Room 101
|
Posted: Fri Jan 02, 2015 6:39 pm Post subject: |
|
|
toralf ...
ok, bug 469976 seems to provide the rational of why its disabled. The specific section {dis,en}abling this is line 128 of the ebuild so its easily copied to a local overlay and uncommented.
best ... khay |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
toralf Developer
data:image/s3,"s3://crabby-images/783ea/783eacf9cb279246e35870bf72711a7ea59f11c1" alt="Developer Developer"
data:image/s3,"s3://crabby-images/7b492/7b4927980d8472dbcc74488b17b964a9a5209e3d" alt=""
Joined: 01 Feb 2004 Posts: 3943 Location: Hamburg
|
Posted: Fri Jan 02, 2015 7:07 pm Post subject: |
|
|
khayyam wrote: | toralf ...
ok, bug 469976 seems to provide the rational of why its disabled. The specific section {dis,en}abling this is line 128 of the ebuild so its easily copied to a local overlay and uncommented.
best ... khay | ick - thx kay for pointing me to that bug, wasn't aware of it.
Well, I'll not test this at my tor relay - so I'll live w/o NIST algos. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|