Re: New crypto in 2.3.4
Denis Corbin <[email protected]> Sat, 21 Jul 2007 16:48:17 +0200
| Newsgroups | gmane.comp.sysutils.backup.dar.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Denis Corbin wrote: [...] >> Denis Corbin wrote: >>> I don't neither, even if the crypto algorithm used was not perfect. >>> Another solution is to keep the original algorithm beside the new and >>> lable the old algorithm "wbf" (or "weak-blowfish"). Thus, having the >>> real blowfish "bf" available in the resulting binary based on the >>> presence of theses offending headers. >> This would be a nice solution, since it would allow "strong blowfish" >> versions of dar to still produce "weak blowfish" archives, if >> compatibility with weak blowfish versions of dar was desired. > > This is also a not too complicated solution. > > note that actually, dar-2.3.4 is able to read encrypted archive > generated with older version of dar. > Well, here what is done in CVS and what will be available with release 2.3.5 about this issue: dar compiles with or without the headers files openssl/evp.h and openssl/hmac.h. If they are missing the new blowfish implementation will not be available only the old implementation will be available. If they are present both new and old implementation will be present. bf or blowfish stay for the new implementation bfw or blowfish_weak design the old implementation weakened by frequent IV collision. For backward compatibility, based on the archive revision (an archive internal number that defines the archive format) dar will apply bfw decryption if the archive has been generated by a dar version older than 2.3.4 even if the user specified 'bf' cipher. For archive generated by more recent version (>= 2.3.4) bf and bfw are two different algorithms and thus cannot be used interchangably. the summary at then end of what the configure script produces as well as 'dar -V' let the user know whether the new blowfish encryption is available or not as well as whether strong encryption is available at all or not. > >> Dave > > Regards, Denis. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGohyxpC5CI8gYGlIRAjEjAKDHN1zI+bD22Rntd3fY+pX3OlA7IgCeLANv b3BsEQUABCQQdTAzY9NTujY= =tC/l -----END PGP SIGNATURE----- ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/