Re: dropbear with external libtommath/libtomcrypt

2016-04-29 Thread Matt Johnston
On Thu, Apr 28, 2016 at 09:31:09AM +0200, Peter Korsgaard wrote: > Thanks. Where did you see Debian using it? Looking at > E.G. > http://http.debian.net/debian/pool/main/d/dropbear/dropbear_2016.73-1.debian.tar.xz > I see they configure with --enable-bundled-libtom. You're right - not sure why I

Re: dropbear with external libtommath/libtomcrypt

2016-04-28 Thread Peter Korsgaard
> "Matt" == Matt Johnston writes: Sorry for the slow response. > Hi Peter, > External libraries are fine - Debian has used them for a > while. Thanks. Where did you see Debian using it? Looking at E.G. http://http.debian.net/debian/pool/main/d/dropbear/dropbear_2016.73-1.debian.tar.xz I

Re: dropbear with external libtommath/libtomcrypt

2016-04-19 Thread Matt Johnston
Hi Peter, External libraries are fine - Debian has used them for a while. The only security-important change is https://secure.ucc.asn.au/hg/dropbear/rev/a55b97f5a485 which I assume is already in buildroot. I've made a few small changes to clear memory or avoid memory allocations - those could go

dropbear with external libtommath/libtomcrypt

2016-04-16 Thread Peter Korsgaard
Hi, We've recently received patches in Buildroot (http://buildroot.org) to build libtommath/libtomcrypt (statically) seperately and link dropbear against those instead of the bundled copies. In general we prefer to use system libraries instead of bundled versions whenever possible, but as dropbea