Bug #66833 [Com]: Default disgest algo is still MD5
| From: | remi@php.net | Date: | Thu, 06 Mar 2014 11:49:13 +0000 |
| Subject: | Bug #66833 [Com]: Default disgest algo is still MD5 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184555@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66833&edit=1
ID: 66833
Comment by: remi@php.net
Reported by: remi@php.net
Summary: Default disgest algo is still MD5
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: GNU/LInux
PHP Version: 5.4.25
Block user comment: N
Private report: N
New Comment:
To be considered: there are still widely used legacy applications that cannot verify signatures that
use sha256.
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 11:43:38] remi@php.net
This change will allow to revert workaround added in
http://git.php.net/?p=php-src.git;a=commitdiff;h=721b9a7c8dbe52cd3f0d2ac69b8eb9c78a0721c9
------------------------------------------------------------------------
[2014-03-06 11:42:43] remi@php.net
Description:
------------
Default disgest algo is still MD5, which means we can generate digest which are rejected on some
recent openssl version (at least RHEL-7 and Fedora 21).
Proposal: switch to sha256 (sha1 is also now considered as unsecure)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66833&edit=1