diff --git a/pkgs/development/libraries/openssl/default.nix b/pkgs/development/libraries/openssl/default.nix index 5d68a79a03b4..2283b0183f87 100644 --- a/pkgs/development/libraries/openssl/default.nix +++ b/pkgs/development/libraries/openssl/default.nix @@ -15,6 +15,11 @@ enableSSL3 ? false, enableMD2 ? false, enableKTLS ? stdenv.hostPlatform.isLinux, + # change this to a value between 0 and 5 (as of OpenSSL 3.5) + # if null, default is used, changes the permitted algorithms + # and key lengths in the default config + # see: https://docs.openssl.org/3.5/man3/SSL_CTX_set_security_level/ + securityLevel ? null, static ? stdenv.hostPlatform.isStatic, # path to openssl.cnf file. will be placed in $etc/etc/ssl/openssl.cnf to replace the default conf ? null, @@ -27,6 +32,9 @@ # cgit) that are needed here should be included directly in Nixpkgs as # files. +# check from time to time, if this range is still correct +assert (securityLevel == null) || (securityLevel >= 0 && securityLevel <= 5); + let common = { @@ -181,6 +189,15 @@ let "-DHAVE_CRYPTODEV" "-DUSE_CRYPTODEV_DIGESTS" ] + # enable optimized EC curve primitives on x86_64, + # can provide a 2x up to 4x speedup at best + # with combined PQC and conventional crypto handshakes + # starting with 3.5 its nice to speed things up for free + ++ lib.optional stdenv.hostPlatform.isx86_64 "enable-ec_nistp_64_gcc_128" + # useful to set e.g. 256 bit security level with setting this to 5 + ++ lib.optional ( + securityLevel != null + ) "-DOPENSSL_TLS_SECURITY_LEVEL=${builtins.toString securityLevel}" ++ lib.optional enableMD2 "enable-md2" ++ lib.optional enableSSL2 "enable-ssl2" ++ lib.optional enableSSL3 "enable-ssl3"