Bug 1020446 - Enable GOST (ECC based) algorithms for DNS resolving
Summary: Enable GOST (ECC based) algorithms for DNS resolving
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: unbound
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Paul Wouters
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: ecc
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-10-17 16:58 UTC by Paul Wouters
Modified: 2015-07-26 20:54 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-07-26 20:54:30 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Paul Wouters 2013-10-17 16:58:56 UTC
Due to legal reasons, unbound was not allowed to be compiled with ghost support. It is compiled using --disable-gost

Some parts of ECC are now being allowed into fedora, but it is unclear whether GOST is an allowed ECC algorithm.

unbound itself provides not ECC - it depends on openssl to provode this.

See also bug#1019390

Comment 1 Jaroslav Reznik 2015-03-03 15:08:57 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle.
Changing version to '22'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22

Comment 2 Tomáš Hozza 2015-04-08 13:01:52 UTC
(In reply to Paul Wouters from comment #0)
> Due to legal reasons, unbound was not allowed to be compiled with ghost
> support. It is compiled using --disable-gost
> 
> Some parts of ECC are now being allowed into fedora, but it is unclear
> whether GOST is an allowed ECC algorithm.

Please note that ldns is compiled with GOST.

Comment 3 Paul Wouters 2015-04-27 17:51:37 UTC
I've rebuild ldns to enable ecdsa but disable gost.

note that ldns doesn't itself do GOST crypto, it uses openssl for that which never has contained gost code (I hope)


Note You need to log in before you can comment on or make changes to this bug.