Re: Crypto overhaul

2017-10-27 Thread Benjamin Kaduk
On Fri, Oct 27, 2017 at 09:20:13PM +0100, Ben Laurie wrote: > On 27 October 2017 at 20:24, Poul-Henning Kamp wrote: > > > > In message > > > > , Ben Laurie writes: > > > >>OpenSSL includes (and is used for) lots of crypto that is not used in > >>SSL - since BearSSL targets SSL/TLS only,

Re: Crypto overhaul

2017-10-27 Thread Jules Gilbert via freebsd-security
These days no one talks about how wonderful CPM was, we used it because at one time, it was the only OS available. So what is our excuse for using SSL?, because I'm fairly certain the NSA and just about everyone else in the neighborhood has hacked it. Question for the group...  Does anyone be

Re: Crypto overhaul

2017-10-27 Thread Ben Laurie
On 27 October 2017 at 20:24, Poul-Henning Kamp wrote: > > In message > > , Ben Laurie writes: > >>OpenSSL includes (and is used for) lots of crypto that is not used in >>SSL - since BearSSL targets SSL/TLS only, it can't, presumably, be >>used to replace all uses of OpenSSL. > > Which i

Re: Crypto overhaul

2017-10-27 Thread Poul-Henning Kamp
In message , Ben Laurie writes: >OpenSSL includes (and is used for) lots of crypto that is not used in >SSL - since BearSSL targets SSL/TLS only, it can't, presumably, be >used to replace all uses of OpenSSL. Which implicitly raises the question if we really need all the boatloads of cr

Re: Crypto overhaul

2017-10-27 Thread John Hein
Eric McCorkle wrote at 20:29 -0400 on Oct 26, 2017: > I was going to wait a bit to discuss this, but it's very pertinent to > the trust infrastructure I described earlier this week. > > There was a good bit of discussion at vBSDCon about a possible crypto > overhaul. This is my understanding

Re: Crypto overhaul

2017-10-27 Thread Igor Mozolevsky
Eric, Have a look at mbedTLS which is now part of ARM: https://tls.mbed.org -- Igor M. ___ freebsd-security@freebsd.org mailing list https://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscr

Re: Crypto overhaul

2017-10-27 Thread Ben Laurie
On 27 October 2017 at 01:29, Eric McCorkle wrote: > I was going to wait a bit to discuss this, but it's very pertinent to > the trust infrastructure I described earlier this week. > > There was a good bit of discussion at vBSDCon about a possible crypto > overhaul. This is my understanding of the