This is the mail archive of the
mailing list for the glibc project.
Re: [RFC][PATCH][BZ 2100] blowfish support in libcrypt
- From: Florian Weimer <fweimer at redhat dot com>
- To: Björn Esser <bjoern dot esser at gmail dot com>
- Cc: libc-alpha at sourceware dot org
- Date: Thu, 1 Jun 2017 11:23:36 +0200
- Subject: Re: [RFC][PATCH][BZ 2100] blowfish support in libcrypt
- Authentication-results: sourceware.org; auth=none
- Authentication-results: ext-mx05.extmail.prod.ext.phx2.redhat.com; dmarc=none (p=none dis=none) header.from=redhat.com
- Authentication-results: ext-mx05.extmail.prod.ext.phx2.redhat.com; spf=pass smtp.mailfrom=fweimer at redhat dot com
- Dkim-filter: OpenDKIM Filter v2.11.0 mx1.redhat.com 8C88D37EEC
- Dmarc-filter: OpenDMARC Filter v1.3.2 mx1.redhat.com 8C88D37EEC
- References: <email@example.com>
On 05/31/2017 07:33 PM, Björn Esser wrote:
> +Solar Designer <solar at openwall.com>
I think we generally prefer patch submission from the original author or
Are the crypt_gensalt functions strongly related to Blowfish support?
In any case, they need documentation, and I'm not sure if the interfaces
are properly designed (haven't looked in detail, admittedly).
The FIPS changes in the patch appear to be incorrect. Surely Blowfish
should be disabled in FIPS mode, too.
The other question is why we should add Blowfish support when the cipher
is pretty much on everyone's banned list.