nuttx-apps/testing/crypto/passwd/Kconfig
Abhishek Mishra 608f13fd4b !fsutils/passwd: Replace TEA with PBKDF2-HMAC-SHA256
Migrate passwd encrypt/verify to PBKDF2 modular crypt format using
kernel cryptodev (CRYPTO_PBKDF2_HMAC_SHA256 via /dev/crypto).  Add
passwd_pbkdf2 wrapper, base64url helpers, complexity validation, and
pbkdf2_test for RFC 6070 vector coverage.  FSUTILS_PASSWD selects
CRYPTO, ALLOW_BSD_COMPONENTS, and CRYPTO_CRYPTODEV so existing sim
defconfigs keep building.  Change NSH_LOGIN_USERNAME default to root and
remove fixed-login password defaults.

BREAKING CHANGE: TEA-encoded /etc/passwd entries no longer verify.
Regenerate each entry after upgrading.  Pair with the nuttx host mkpasswd
changes in apache/nuttx#19209.  Boards must enable the appropriate
software or hardware crypto backend for PBKDF2 at runtime.  When
CONFIG_NSH_LOGIN_FIXED=y, set CONFIG_NSH_LOGIN_PASSWORD in the board
defconfig or menuconfig; there is no default password.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-07-22 17:21:22 +08:00

34 lines
989 B
Text

#
# For a description of the syntax of this configuration file,
# see the file kconfig-language.txt in the NuttX tools repository.
#
config TESTING_PBKDF2
tristate "PBKDF2 and passwd hash test"
default n
depends on FSUTILS_PASSWD
---help---
Enable the PBKDF2-HMAC-SHA256 unit test
(apps/testing/crypto/passwd). Always runs RFC 6070 SHA-256
vectors. The passwd_encrypt / passwd_verify round-trip runs only
when FSUTILS_PASSWD_READONLY is disabled and DEV_URANDOM is
enabled; otherwise it is skipped with an explanatory message.
if TESTING_PBKDF2
config TESTING_PBKDF2_PRIORITY
int "pbkdf2_test task priority"
default 100
config TESTING_PBKDF2_STACKSIZE
int "pbkdf2_test stack size"
default DEFAULT_TASK_STACKSIZE
config TESTING_PBKDF2_SLOW_VECTOR
bool "Run RFC 6070 vector with 16777216 iterations"
default n
---help---
Include RFC 6070 test vector #4 (16,777,216 iterations). This
takes a long time on embedded targets; enable only for manual runs.
endif