News: 0001475398

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ubuntu Developing "crypto-config" For System-Wide Cryptography Configuration

([Ubuntu] 3 Hours Ago crypto-config)


A new Ubuntu utility seeing an uptick in development recently is crypto-config as a means of system-wide cryptography configuration.

Crypto-config has been quietly in development since last year but seemingly now taking on more development load being past the Ubuntu 24.04 LTS phase. In last week's Ubuntu Foundations Team Updates it was [1]described by Canonical engineer Adrien Nader as:

Work on crypto-config for system-wide configuration of cryptography

Updated code against latest specification, fixed several small issues

Added temporary code to be able to not be a dependency of the configured packages

Started preparing demonstration profiles

looked at gnutls’ configuration handling to add drop-ins support

looked at nginx’ configuration which prevents disabling TLS versions after they’ve been enabled once

Crypto-config isn't currently relied upon by Ubuntu but is under active development. There is [2]a PPA for offering the latest crypto-config packages for those interested. The upstream code for crypto-config is currently on [3]GitLab .

Documentation is light but crypto-config currently is aiming to be a means of system-wide cryptography configuration profile management. There are currently profiles for managing the crypto settings around Apt, Nginx, GnuTLS, and OpenSSL. It will be interesting to see what comes of crypto-config for easing crypto settings management in future Ubuntu releases.



[1] https://discourse.ubuntu.com/t/foundations-team-updates-thursday-2024-06-27/45926/4

[2] https://launchpad.net/~adrien/+archive/ubuntu/crypto-config/+packages

[3] https://gitlab.com/crypto-config/crypto-config/



milo_hoffman

Britoid

Jumbotron

mortn

We may not be able to persuade Hindus that Jesus and not Vishnu should
govern their spiritual horizon, nor Moslems that Lord Buddha is at the
center of their spiritual universe, nor Hebrews that Mohammed is a major
prophet, nor Christians that Shinto best expresses their spiritual
concerns, to say nothing of the fact that we may not be able to get
Christians to agree among themselves about their relationship to God.
But all will agree on a proposition that they possess profound spiritual
resources. If, in addition, we can get them to accept the further
proposition that whatever form the Deity may have in their own theology,
the Deity is not only external, but internal and acts through them, and
they themselves give proof or disproof of the Deity in what they do and
think; if this further proposition can be accepted, then we come that
much closer to a truly religious situation on earth.
-- Norman Cousins, from his book "Human Options"