Bug #66833 [Com]: Default disgest algo is still MD5
| From: | remi@php.net | Date: | Thu, 06 Mar 2014 12:53:14 +0000 |
| Subject: | Bug #66833 [Com]: Default disgest algo is still MD5 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184566@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66833&edit=1
ID: 66833
Comment by: remi@php.net
Reported by: remi@php.net
Summary: Default disgest algo is still MD5
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: GNU/LInux
PHP Version: 5.4.25
Block user comment: N
Private report: N
New Comment:
After a deeper analysis:
Most PHP users will rely on system configuration (so sha1 or sha256 on modern distro)
So this only affects user which use a non-default configuration, without default_md option (as in
the ext/openssl/tests/bug36732.phpt test).
So switch to EVP_sha1() seems the simple solution, less risky, and will match recent openssl library
hardcoded value (sha256 is only set in the provided configuration).
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 12:24:10] remi@php.net
The following patch has been added/updated:
Patch Name: openssl-defaultmd-sha1.patch
Revision: 1394108650
URL: https://bugs.php.net/patch-display.php?bug=66833&patch=openssl-defaultmd-sha1.patch&revision=1394108650
------------------------------------------------------------------------
[2014-03-06 11:49:13] remi@php.net
To be considered: there are still widely used legacy applications that cannot verify signatures that
use sha256.
------------------------------------------------------------------------
[2014-03-06 11:43:38] remi@php.net
This change will allow to revert workaround added in
http://git.php.net/?p=php-src.git;a=commitdiff;h=721b9a7c8dbe52cd3f0d2ac69b8eb9c78a0721c9
------------------------------------------------------------------------
[2014-03-06 11:42:43] remi@php.net
Description:
------------
Default disgest algo is still MD5, which means we can generate digest which are rejected on some
recent openssl version (at least RHEL-7 and Fedora 21).
Proposal: switch to sha256 (sha1 is also now considered as unsecure)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66833&edit=1