Why still no PKCS#11 ECC key support in OpenSSH ?

Damien Miller djm at mindrot.org
Mon Aug 13 12:45:11 AEST 2018


On Sun, 12 Aug 2018, Blumenthal, Uri - 0553 - MITLL wrote:

> Tone aside, let me second what Bob said. OpenSSH maintainers seem to
> be able to find time for many updates and upgrades - but ECC support
> over PKCS#11 appears to repulse them for more than two years (I don't
> care to check for exactly how many more).

There's no "repulsion" involved, just a lack of time coupled with a lot
of unfinished work and the costs (for me at least) of ramping up on
an unfamiliar API (PKCS#11).

-d


More information about the openssh-unix-dev mailing list