Commit 52881b

2025-05-27 14:39:25 flichtenheld: typo fixes
PQCryptoOpenVPN.md ..
@@ 30,7 30,7 @@
[Perfect Forward Secrecy](https://de.wikipedia.org/wiki/Perfect_Forward_Secrecy)
and typically achieved by using finite field Diffie-Hellmann (see also `--dh`) or
[Elliptic-curve Diffie–Hellman](https://en.wikipedia.org/wiki/Elliptic-curve_Diffie–Hellman).
- TLS 1.3 typically use the ECDH with the X25519 curve for the key agreemnt.
+ TLS 1.3 typically uses ECDH with the X25519 curve for the key agreemnt.
For achieving perfect foward secrecy with post-quantum a
[hybrid ECDHE-MLKEM Key Agreement](https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/) is
@@ 45,24 45,24 @@
tls-groups X25519MLKEM768
- will only allow connections that use this post-quantum safe key-agreement. A connection that cannot fulfil this will
+ will only allow connections that use this post-quantum safe key-agreement. A connection that cannot fullfil this will
fail similar to this:
OpenSSL: error:0A000065:SSL routines::no suitable key share:
This also requires OpenVPN to be used with a TLS library that supports these new key-agreement algorithms like
- OpenSSL 3.5.0,
+ OpenSSL 3.5.0.
Using a post-quantum key-agreement is also what currently (in 2025) people are talking about when they talking about
- software including post-qunatum crypto.
+ software including post-quantum crypto.
- # Post-quantum signing singing/certificates
+ # Post-quantum signing/certificates
- Having post-quantum key-agreement is much critical right now. Especially for a TLS/VPN connection where verification of
+ Having post-quantum key-agreement is much more critical right now. Especially for a TLS/VPN connection where verification of
certificates is only needed for the connection itself and being able to verify signatures and identity later is at
least currently of lesser concern. So at least at the moment, the urgency here is not as big as it is for the key-agreement.
- But creating certificates with post-quantum algorithm is also possible. E.g. creating a self-signed certificate that is usable with
- `--peer-fingerprint` using the ML-DSA-65 algorith cna be done using OpenSSL (3.5.0 or later):
+ But creating certificates with post-quantum algorithms is also possible. E.g. creating a self-signed certificate that is usable with
+ `--peer-fingerprint` using the ML-DSA-65 algorith can be created using OpenSSL (3.5.0 or later):
openssl req -x509 -newkey ML-DSA-65 -keyout styx-mldsa-65.key -out styx-mldsa-65.key -nodes -sha256 -days 3650 -subj '/CN=styx-mldsa-65'
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9