Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 19 Nov 2014 14:42:30 +0200
From:      Beeblebrox <zaphod@berentweb.com>
To:        freebsd-questions@freebsd.org
Subject:   Enable elliptic curve NISTP in openssl from base
Message-ID:  <20141119144230.726806f7@rsbsd.rsb>

next in thread | raw e-mail | index | archive | help
My TOR log shows below for start up. I don't have security/openssl installe=
d as I'm using that from base. Also that's not among the depends ports for =
security/tor.

"We were built to run on a 64-bit CPU, with OpenSSL 1.0.1 or later, but wit=
h a version of OpenSSL that apparently lacks accelerated support for the NI=
ST P-224 and P-256 groups. Building openssl with such support (using the en=
able-ec_nistp_64_gcc_128 option when configuring it) would make ECDH much f=
aster."

I cannot find any extra setting in /etc/src.conf that would enable this. Th=
e man page mentions EC, and I have generated SSL/EC keys as test which work=
s.

I don't know where to look from here.

--=20
FreeBSD_amd64_11-Current_RadeonKMS



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20141119144230.726806f7>