Skip to content

Commit

Permalink
Strengthen warning in CONFIGURE.md
Browse files Browse the repository at this point in the history
  • Loading branch information
SWilson4 committed May 23, 2024
1 parent 8e75f98 commit ca27922
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions CONFIGURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,9 @@ If `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature v
Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys.
Keys stored in a file system are extremely susceptible to simultaneous use.
When enabled in this library a warning message will be generated by the config process.
The name of the configuration variable has been chosen to make every user of this feature aware of its security risks.
The OQS team explicitly discourages enabling this variable and reserves the right to remove this feature in future releases if its use causes actual harm.
It remains present as long as it is responsibly used as per the stated warnings.

By default,
- `OQS_ENABLE_SIG_STFL_XMSS` is `OFF`
Expand Down

0 comments on commit ca27922

Please sign in to comment.