New ciphers in OpenSense

Started by Linfern, March 18, 2023, 05:53:00 AM

Previous topic - Next topic
Hello!
The question is: how can I add support for Russian GOST encryption algorithms to OpenSense?
What steps need to be taken for this?
Maybe someone has ready-made images for this.

March 18, 2023, 12:10:37 PM #1 Last Edit: March 18, 2023, 12:14:29 PM by meyergru
I bet this would be hard and I doubt anyone has done this:

1. Current OpnSense versions have dropped support for LibreSSL and rely on OpenSSL 1.1.1.
2. OpenSSL has dropped GOST support since 1.1.0 (https://techglimpse.com/solved-openssl-library-has-no-gost-support/) - and for a good reason.

Before you bother to look into this, have a look at the cryptanalysis section here: https://en.wikipedia.org/wiki/GOST_(block_cipher)#Cryptanalysis_of_GOST - essentially, GOST is a weak cipher.
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 800 up, Bufferbloat A+