[22280] New property to select preferred key agreement algorithm (backport #5413) (backport #5442) #5445
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
DDS security specifies the possibility of selecting the key agreement algorithm used to generate the shared secret at the end of the authentication phase.
The Fast DDS documentation indicates that
Elliptic Curve Diffie-Hellman (ECDH)
is used, but this is only the case if a participant from other vendor starts the authentication and proposes that method.This pull request:
dds.sec.auth.builtin.PKI-DH.preferred_key_agreement
property that allows choosing the preferred algorithm to use.@Mergifyio backport 3.1.x
We will backport to 3.1.x, but leaving the default value of the new property to the old behavior.
We will then backport from there into 3.0.x 2.14.x 2.10.x
Contributor Checklist
versions.md
file (if applicable).preferred_key_agreement
property Fast-DDS-docs#963Reviewer Checklist
This is an automatic backport of pull request #5413 done by [Mergify](https://mergify.com).
This is an automatic backport of pull request #5442 done by [Mergify](https://mergify.com).