Ad Widget

Collapse

Elliptic Curve Based Certificates

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • TiddleMiddle
    Junior Member
    • Nov 2019
    • 5

    #1

    Elliptic Curve Based Certificates

    I have successfully used RSA based certificates in my Zabbix set up, and decided to try ECC based certs for performance reasons.

    I tried with both CentOS and Ubuntu agents, with an OpenBSD server. Ubuntu had been giving me GnuTLS Negotiation Errors, and Centos seemed to be having a possibly unrelated issue with permissions (probably SELinux).

    I used Openssl/libressl "openssl ecparam -genkey -name secp521r1 -out agent.key"

    Has anyone had success with with ECC on zabbix? What particular curve worked?
  • kloczek
    Senior Member
    • Jun 2006
    • 1771

    #2
    That may depends on your distribution.
    IIRC gnutls does not handle elliptic curve encryption.
    Most of the Linux distros have disabled that encryption in opessl as well (restrictions).
    http://uk.linkedin.com/pub/tomasz-k%...zko/6/940/430/
    https://kloczek.wordpress.com/
    zapish - Zabbix API SHell binding https://github.com/kloczek/zapish
    My zabbix templates https://github.com/kloczek/zabbix-templates

    Comment

    Working...