vishalmishra434 / rpms / openssh

Forked from rpms/openssh 3 months ago
Clone
Petr Lautrbach 1f3640
diff -U0 openssh-6.3p1/ChangeLog.df openssh-6.3p1/ChangeLog
Petr Lautrbach 1f3640
--- openssh-6.3p1/ChangeLog.df	2013-10-23 22:38:03.476272461 +0200
Petr Lautrbach 1f3640
+++ openssh-6.3p1/ChangeLog	2013-10-23 22:39:46.051788366 +0200
Petr Lautrbach 1f3640
@@ -0,0 +1,8 @@
Petr Lautrbach 1f3640
+20131010
Petr Lautrbach 1f3640
+ - dtucker@cvs.openbsd.org 2013/10/08 11:42:13
Petr Lautrbach 1f3640
+   [dh.c dh.h]
Petr Lautrbach 1f3640
+   Increase the size of the Diffie-Hellman groups requested for a each
Petr Lautrbach 1f3640
+   symmetric key size.  New values from NIST Special Publication 800-57 with
Petr Lautrbach 1f3640
+   the upper limit specified by RFC4419.  Pointed out by Peter Backes, ok
Petr Lautrbach 1f3640
+   djm@.
Petr Lautrbach 1f3640
+
Petr Lautrbach 1f3640
diff -up openssh-6.3p1/dh.c.df openssh-6.3p1/dh.c
Petr Lautrbach 1f3640
--- openssh-6.3p1/dh.c.df	2013-07-18 08:12:07.000000000 +0200
Petr Lautrbach 1f3640
+++ openssh-6.3p1/dh.c	2013-10-23 22:38:03.476272461 +0200
Petr Lautrbach 1f3640
@@ -1,4 +1,4 @@
Petr Lautrbach 1f3640
-/* $OpenBSD: dh.c,v 1.51 2013/07/02 12:31:43 markus Exp $ */
Petr Lautrbach 1f3640
+/* $OpenBSD: dh.c,v 1.52 2013/10/08 11:42:13 dtucker Exp $ */
Petr Lautrbach 1f3640
 /*
Petr Lautrbach 1f3640
  * Copyright (c) 2000 Niels Provos.  All rights reserved.
Petr Lautrbach 1f3640
  *
Petr Lautrbach 1f3640
@@ -352,17 +352,20 @@ dh_new_group14(void)
Petr Lautrbach 1f3640
 
Petr Lautrbach 1f3640
 /*
Petr Lautrbach 1f3640
  * Estimates the group order for a Diffie-Hellman group that has an
Petr Lautrbach 1f3640
- * attack complexity approximately the same as O(2**bits).  Estimate
Petr Lautrbach 1f3640
- * with:  O(exp(1.9223 * (ln q)^(1/3) (ln ln q)^(2/3)))
Petr Lautrbach 1f3640
+ * attack complexity approximately the same as O(2**bits).
Petr Lautrbach 1f3640
+ * Values from NIST Special Publication 800-57: Recommendation for Key
Petr Lautrbach 1f3640
+ * Management Part 1 (rev 3) limited by the recommended maximum value
Petr Lautrbach 1f3640
+ * from RFC4419 section 3.
Petr Lautrbach 1f3640
  */
Petr Lautrbach 1f3640
 
Petr Lautrbach 1f3640
 int
Petr Lautrbach 1f3640
 dh_estimate(int bits)
Petr Lautrbach 1f3640
 {
Petr Lautrbach 1f3640
-
Petr Lautrbach 1f3640
+	if (bits <= 112)
Petr Lautrbach 1f3640
+		return 2048;
Petr Lautrbach 1f3640
 	if (bits <= 128)
Petr Lautrbach 1f3640
-		return (1024);	/* O(2**86) */
Petr Lautrbach 1f3640
+		return 3072;
Petr Lautrbach 1f3640
 	if (bits <= 192)
Petr Lautrbach 1f3640
-		return (2048);	/* O(2**116) */
Petr Lautrbach 1f3640
-	return (4096);		/* O(2**156) */
Petr Lautrbach 1f3640
+		return 7680;
Petr Lautrbach 1f3640
+	return 8192;
Petr Lautrbach 1f3640
 }
Petr Lautrbach 1f3640
diff -up openssh-6.3p1/dh.h.df openssh-6.3p1/dh.h
Petr Lautrbach 1f3640
--- openssh-6.3p1/dh.h.df	2008-06-29 14:47:04.000000000 +0200
Petr Lautrbach 1f3640
+++ openssh-6.3p1/dh.h	2013-10-23 22:38:03.476272461 +0200
Petr Lautrbach 1f3640
@@ -1,4 +1,4 @@
Petr Lautrbach 1f3640
-/* $OpenBSD: dh.h,v 1.10 2008/06/26 09:19:40 djm Exp $ */
Petr Lautrbach 1f3640
+/* $OpenBSD: dh.h,v 1.11 2013/10/08 11:42:13 dtucker Exp $ */
Petr Lautrbach 1f3640
 
Petr Lautrbach 1f3640
 /*
Petr Lautrbach 1f3640
  * Copyright (c) 2000 Niels Provos.  All rights reserved.
Petr Lautrbach 1f3640
@@ -43,6 +43,7 @@ int	 dh_pub_is_valid(DH *, BIGNUM *);
Petr Lautrbach 1f3640
 
Petr Lautrbach 1f3640
 int	 dh_estimate(int);
Petr Lautrbach 1f3640
 
Petr Lautrbach 1f3640
+/* Min and max values from RFC4419. */
Petr Lautrbach 1f3640
 #define DH_GRP_MIN	1024
Petr Lautrbach 1f3640
 #define DH_GRP_MAX	8192
Petr Lautrbach 1f3640