Dropbear support for ecdsa-sha2-nistp256 keys

On my GL-X3000 (OpenWrt 21.02-SNAPSHOT, r15812+882-46b6ee7ffc), I cannot authenticate over SSH using an ECDSA key, ecdsa-sha2-nistp256. This is the key type that can be stored securely within the Secure Enclave on Macs, which allows biometric authentication to the router.

Could Dropbear be compiled with DROPBEAR_ECC to support this algorithm?

Hello,

I will try to evaluate this request for the Dropbear.

Thanks.

1 Like

Hello,

Try testing this temporary firmware for X3000, the dropbear compiles integrated ecdsa.

Hi, thanks for creating this. The transfer has already expired, could you please re-upload it?

Please check the attach

Thank you, I downloaded it. Before I install it -- I notice that the file is almost 10 MB smaller than the released firmware file openwrt-x3000-4.7.1-0106-1736138495.bin. Is that expected?

yes, this test firmware is only used to test dropbear's ecdsa.