HomeClusterLabs Projects

reduce minimum crypto key size to 1024bit

Description

reduce minimum crypto key size to 1024bit

Since the key is used for AES/3DES and HMAC operations only, this is
safe. AES/3DES use keys in the 128- to 256-bit range, HMAC with
MD5/SHA1/SHA2 should use keys with a minimum of 128- to 512-bit (in both
cases, depending on the actual algorithm used).

This reduction also keeps knet compatible with existing Corosync 2.x
keyfiles, which are 1024-bit.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>

Details

Provenance
Fabian Grünbichler <f.gruenbichler@proxmox.com>Authored on Apr 3 2019, 8:28 AM
fabbioneCommitted on Apr 9 2019, 9:33 AM
Parents
rKa6746007986b: [build] add another exception to valgrind nss combo
Branches
Unknown
Tags
Unknown

Event Timeline