[Cryptography-dev] Criteria for first release?

Alex Gaynor alex.gaynor at gmail.com
Thu Oct 24 18:38:00 CEST 2013


On Thu, Oct 24, 2013 at 8:32 AM, Donald Stufft <donald at stufft.io> wrote:

>
> On Oct 24, 2013, at 11:27 AM, Alex Gaynor <alex.gaynor at gmail.com> wrote:
>
> > Hi all!
> >
> > We're at an exciting point where it's actually possible to do stuff with
> cryptography. You know what that means... time to start thinking about a
> release! I'd like us to make a list of the stuff we think should be in our
> first release. Here's my list:
> >
> > * Figure out our packaging / bundling story with OpenSSL
> > * Finish binding OpenSSL to the point where JP can use it for PyOpenSSL
> > * The last two block ciphers that conch would need (CAST and Blowfish)
> > * Finalizing the iterator APIs for BlockCipher
> > * Padding APIs
> >
> > Here's stuff I'm not sure about:
> > * Everything that conch needs (this means figuring out the API for
> RSA/DSA)
> > * GCM
> > * CommonCrypto backend
>
> I’d really like to get GCM and RSA into it, GCM is something I think all
> of us wanted
> which we punted on to get the easier modes sorted out first. Without RSA
> we don’t
> have *any* asymmetric ciphers which is kinda lame.
>
> CommonCrypto I’m meh on.
>
> >
> > What do ya'll think, am I missing anything, do I have to much?
> >
> > As a heads up: once we're ready to do the release and we've frozen a
> release-candidate I plan to investigate getting it audited.
>
> Whose going to pay for an audit?
>
>
I'm going to try to get some security firms to donate it. Failing that
<we'll see>.


> >
> > Alex
> >
> > --
> > "I disapprove of what you say, but I will defend to the death your right
> to say it." -- Evelyn Beatrice Hall (summarizing Voltaire)
> > "The people's good is the highest law." -- Cicero
> > GPG Key fingerprint: 125F 5C67 DFE9 4084
> > _______________________________________________
> > Cryptography-dev mailing list
> > Cryptography-dev at python.org
> > https://mail.python.org/mailman/listinfo/cryptography-dev
>
>
> -----------------
> Donald Stufft
> PGP: 0x6E3CBCE93372DCFA // 7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372
> DCFA
>
>
> _______________________________________________
> Cryptography-dev mailing list
> Cryptography-dev at python.org
> https://mail.python.org/mailman/listinfo/cryptography-dev
>
>
Alex

-- 
"I disapprove of what you say, but I will defend to the death your right to
say it." -- Evelyn Beatrice Hall (summarizing Voltaire)
"The people's good is the highest law." -- Cicero
GPG Key fingerprint: 125F 5C67 DFE9 4084
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.python.org/pipermail/cryptography-dev/attachments/20131024/5c2cbf1d/attachment.html>


More information about the Cryptography-dev mailing list