[Opendnssec-user] Plans for ECDSA support in softhsm(2)

Tom Hendrikx tom at whyscream.net
Sun Mar 6 20:50:43 UTC 2016


Hi,

I'm not a crypto guru , but always interested in new things. As I'm
currently migrating my DNSSEC signing setup, I was looking into stuff to
improve. I saw that a few new algorithms were introduced since my last
setup, namely ECDSAP256SHA256 and ECDSAP384SHA384 (resp. algorithm 13
and 14 from IANA registry).

After trying to get that working with softhsm, I was told:

ods-enforcerd: Key algorithm 13 unsupported by libhsm, exiting...

So I went and setup softhsm2, which took some time (the ubuntu wily
package is a bit rough still), but this resulted in the exact same error
(also for algo 14).

Are there any plans for ECDSA support? I didn't find any github tickets
either mentioning this...

Regards,
	Tom

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20160306/08f3400a/attachment.bin>


More information about the Opendnssec-user mailing list