Jira (PUP-2606) Support ECC keys

2 views
Skip to first unread message

Aaron Armstrong (JIRA)

unread,
Dec 29, 2014, 2:50:33 PM12/29/14
to puppe...@googlegroups.com
Aaron Armstrong updated an issue
 
Puppet / New Feature PUP-2606
Support ECC keys
Change By: Aaron Armstrong
Component/s: Networking Services
Component/s: Puppet Server
Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v6.3.10#6340-sha1:7ea293a)
Atlassian logo

Yuri A (JIRA)

unread,
Sep 27, 2016, 12:06:06 PM9/27/16
to puppe...@googlegroups.com
Yuri A commented on New Feature PUP-2606
 
Re: Support ECC keys

What's the trouble here? Can we get this moving? We're using our own CA and would like to use ECC.

This message was sent by Atlassian JIRA (v6.4.14#64029-sha1:ae256fe)
Atlassian logo

Eric Sorenson (JIRA)

unread,
Sep 27, 2016, 2:21:10 PM9/27/16
to puppe...@googlegroups.com
Eric Sorenson commented on New Feature PUP-2606
 
Re: Support ECC keys

Yuri A not many people have asked for this so it hasn't gotten prioritized. I will take this as a design consideration as we look at revamping the CA and server/agent SSL interactions.

Andrew Forgue (JIRA)

unread,
Jan 17, 2017, 4:59:02 PM1/17/17
to puppe...@googlegroups.com
Andrew Forgue commented on New Feature PUP-2606
 
Re: Support ECC keys

+1 – We're super interested in this as well (on the Agent Side), since we use an external CA and only issue EC keys.

Eric Sorenson (JIRA)

unread,
Jan 17, 2017, 6:14:25 PM1/17/17
to puppe...@googlegroups.com
Eric Sorenson updated an issue
Change By: Eric Sorenson
Fix Version/s: PUP 4.y

Branan Riley (JIRA)

unread,
May 15, 2017, 7:01:03 PM5/15/17
to puppe...@googlegroups.com
Branan Riley updated an issue
Change By: Branan Riley
Labels: redmine  triaged

Branan Riley (JIRA)

unread,
May 15, 2017, 7:01:04 PM5/15/17
to puppe...@googlegroups.com
Branan Riley updated an issue
Change By: Branan Riley
Team: Agent

Moses Mendoza (JIRA)

unread,
May 18, 2017, 1:46:11 PM5/18/17
to puppe...@googlegroups.com
Moses Mendoza updated an issue
Change By: Moses Mendoza
Labels: redmine  triaged

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:13:03 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Team: Server Coremunity
This message was sent by Atlassian JIRA (v7.7.1#77002-sha1:e75ca93)
Atlassian logo

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:15:03 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper commented on New Feature PUP-2606
 
Re: Support ECC keys

ECC is desirable for agents because it requires less CPU and power than RSA for the same effective level of security. I've moved this to Coremunity and implemented a PR enabling the agent to use EC keys, which is compatible when servers are using RSA keys. We will need to file additional tickets if/when we add server support.

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:15:04 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper assigned an issue to Josh Cooper
Change By: Josh Cooper
Assignee: Josh Cooper

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:16:04 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Fix Version/s: PUP 6.5.0

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:20:03 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Release Notes Summary: An agent may be configured to use elliptic curve (EC) private keys using the `key_type=ec` puppet setting. By default, puppet will use the `prime256v1` elliptic curve, but an alternate curve may be specified using the `named_curve` puppet setting, provided ruby and openssl support it. See OpenSSL::PKey::EC.builtin_curves for a list of supported curves. Note the `key_type` and `named_curve` settings are ignored if the agent already has a private key. Also the settings only control the type of private key that the agent generates. It does not affect which curve is selected in the TLS protocol.
Release Notes: New Feature

Josh Cooper (JIRA)

unread,
Apr 24, 2019, 3:21:03 PM4/24/19
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Sprint: Platform Core KANBAN

Jacob Helwig (JIRA)

unread,
May 1, 2019, 2:30:03 PM5/1/19
to puppe...@googlegroups.com
Jacob Helwig commented on New Feature PUP-2606
 
Re: Support ECC keys

Merged to master branch in 3b9b1a32a4.

Kris Bosland (JIRA)

unread,
May 3, 2019, 6:19:03 PM5/3/19
to puppe...@googlegroups.com
Kris Bosland commented on New Feature PUP-2606
 
Re: Support ECC keys

Merged #7505 into master at 4baeed9.

Heston Hoffman (JIRA)

unread,
Jun 12, 2019, 5:05:03 PM6/12/19
to puppe...@googlegroups.com
Heston Hoffman updated an issue
Change By: Heston Hoffman
Labels: redmine resolved-issue-added
Reply all
Reply to author
Forward
0 new messages