Bug #66833 [Com]: Default disgest algo is still MD5

From: Date: Thu, 06 Mar 2014 12:53:14 +0000
Subject: Bug #66833 [Com]: Default disgest algo is still MD5
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184566@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66833&edit=1 ID: 66833 Comment by: remi@php.net Reported by: remi@php.net Summary: Default disgest algo is still MD5 Status: Open Type: Bug Package: OpenSSL related Operating System: GNU/LInux PHP Version: 5.4.25 Block user comment: N Private report: N New Comment: After a deeper analysis: Most PHP users will rely on system configuration (so sha1 or sha256 on modern distro) So this only affects user which use a non-default configuration, without default_md option (as in the ext/openssl/tests/bug36732.phpt test). So switch to EVP_sha1() seems the simple solution, less risky, and will match recent openssl library hardcoded value (sha256 is only set in the provided configuration). Previous Comments: ------------------------------------------------------------------------ [2014-03-06 12:24:10] remi@php.net The following patch has been added/updated: Patch Name: openssl-defaultmd-sha1.patch Revision: 1394108650 URL: https://bugs.php.net/patch-display.php?bug=66833&patch=openssl-defaultmd-sha1.patch&revision=1394108650 ------------------------------------------------------------------------ [2014-03-06 11:49:13] remi@php.net To be considered: there are still widely used legacy applications that cannot verify signatures that use sha256. ------------------------------------------------------------------------ [2014-03-06 11:43:38] remi@php.net This change will allow to revert workaround added in http://git.php.net/?p=php-src.git;a=commitdiff;h=721b9a7c8dbe52cd3f0d2ac69b8eb9c78a0721c9 ------------------------------------------------------------------------ [2014-03-06 11:42:43] remi@php.net Description: ------------ Default disgest algo is still MD5, which means we can generate digest which are rejected on some recent openssl version (at least RHEL-7 and Fedora 21). Proposal: switch to sha256 (sha1 is also now considered as unsecure) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66833&edit=1

« previous php.bugs (#184566) next »