[openssl-commits] [openssl] master update

Rich Salz rsalz at openssl.org
Fri Dec 11 17:00:27 UTC 2015


The branch master has been updated
       via  f8547f62c212837dbf44fb7e2755e5774a59a57b (commit)
      from  6ebe8dac3e6101c00b973ec8abc3cf405c9070d5 (commit)


- Log -----------------------------------------------------------------
commit f8547f62c212837dbf44fb7e2755e5774a59a57b
Author: Rich Salz <rsalz at akamai.com>
Date:   Sat Jun 13 17:03:39 2015 -0400

    Use SHA256 not MD5 as default digest.
    
    Reviewed-by: Viktor Dukhovni <viktor at openssl.org>

-----------------------------------------------------------------------

Summary of changes:
 apps/ca.c   | 2 +-
 apps/dgst.c | 2 +-
 apps/enc.c  | 2 +-
 3 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/apps/ca.c b/apps/ca.c
index f6ba239..535526c 100644
--- a/apps/ca.c
+++ b/apps/ca.c
@@ -1420,7 +1420,7 @@ static int certify_cert(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
     } else
         BIO_printf(bio_err, "Signature ok\n");
 
-    if ((rreq = X509_to_X509_REQ(req, NULL, EVP_md5())) == NULL)
+    if ((rreq = X509_to_X509_REQ(req, NULL, NULL)) == NULL)
         goto end;
 
     ok = do_body(xret, pkey, x509, dgst, sigopts, policy, db, serial, subj,
diff --git a/apps/dgst.c b/apps/dgst.c
index e62a8de..fb09a45 100644
--- a/apps/dgst.c
+++ b/apps/dgst.c
@@ -375,7 +375,7 @@ int dgst_main(int argc, char **argv)
             goto end;
         }
         if (md == NULL)
-            md = EVP_md5();
+            md = EVP_sha256();
         if (!EVP_DigestInit_ex(mctx, md, impl)) {
             BIO_printf(bio_err, "Error setting digest\n");
             ERR_print_errors(bio_err);
diff --git a/apps/enc.c b/apps/enc.c
index b0c82d6..cf02185 100644
--- a/apps/enc.c
+++ b/apps/enc.c
@@ -306,7 +306,7 @@ int enc_main(int argc, char **argv)
     }
 
     if (dgst == NULL)
-        dgst = EVP_md5();
+        dgst = EVP_sha256();
 
     /* It must be large enough for a base64 encoded line */
     if (base64 && bsize < 80)


More information about the openssl-commits mailing list