nmap / nmap/nmap

Support building Nmap with AWS-LC

Open
#3,044 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
13.6k
Forks
2.9k
PR merge metrics
No merged PRs in 30d

Description

Hello,

I’m an engineer at AWS working on AWS Libcrypto (AWS-LC), an open-source cryptographic library maintained for AWS and their customers. We are committed to backwards compatibility. For this purpose we have CI jobs here asserting every change’s compatibility with many different open-source projects. We use these tests to catch compatibility regressions before they’re merged. We have already added Nmap to our CI here.

AWS-LC supports CPU-specific performance optimizations for AWS Graviton 2, AWS Graviton 3, and Intel x86-64 with AVX-512 instructions. We’ve formally verified a subset of AWS-LC’s cryptographic primitives, and continue to invest in expanding this coverage. AWS-LC has been FIPS validated by NIST and we have 140-3 certificates for both dynamic and static builds. We would like to upstream support for AWS-LC into the mainline branch of Nmap. We believe that this would provide the best experience for users wishing to build Nmap against AWS-LC.

We support all features of Nmap with one caveat provided in the patch file here. The provided patch requires only a minor modification - adding the OPENSSL_IS_AWSLC macro to an existing ifdef block.

If you agree that this integration would be useful, I’d be happy to put together a PR.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with tests/ci/integration/nmap_patch/aws-lc-nmap.patch and locate the existing ifdef block it changes. Apply the equivalent AWS-LC compatibility adjustment, build Nmap against AWS-LC, and verify that the supported features continue to build successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, c
Domain
build-system, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
50/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.