提交 be681e12 编写于 作者: D Dr. Stephen Henson

don't use pseudo digests for default values of keys

上级 6251989e
...@@ -164,14 +164,14 @@ void ssl_cert_set_default_md(CERT *cert) ...@@ -164,14 +164,14 @@ void ssl_cert_set_default_md(CERT *cert)
{ {
/* Set digest values to defaults */ /* Set digest values to defaults */
#ifndef OPENSSL_NO_DSA #ifndef OPENSSL_NO_DSA
cert->pkeys[SSL_PKEY_DSA_SIGN].digest = EVP_dss1(); cert->pkeys[SSL_PKEY_DSA_SIGN].digest = EVP_sha1();
#endif #endif
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
cert->pkeys[SSL_PKEY_RSA_SIGN].digest = EVP_sha1(); cert->pkeys[SSL_PKEY_RSA_SIGN].digest = EVP_sha1();
cert->pkeys[SSL_PKEY_RSA_ENC].digest = EVP_sha1(); cert->pkeys[SSL_PKEY_RSA_ENC].digest = EVP_sha1();
#endif #endif
#ifndef OPENSSL_NO_ECDSA #ifndef OPENSSL_NO_ECDSA
cert->pkeys[SSL_PKEY_ECC].digest = EVP_ecdsa(); cert->pkeys[SSL_PKEY_ECC].digest = EVP_sha1();
#endif #endif
} }
......
...@@ -3055,7 +3055,7 @@ int tls1_process_sigalgs(SSL *s, const unsigned char *data, int dsize) ...@@ -3055,7 +3055,7 @@ int tls1_process_sigalgs(SSL *s, const unsigned char *data, int dsize)
*/ */
#ifndef OPENSSL_NO_DSA #ifndef OPENSSL_NO_DSA
if (!c->pkeys[SSL_PKEY_DSA_SIGN].digest) if (!c->pkeys[SSL_PKEY_DSA_SIGN].digest)
c->pkeys[SSL_PKEY_DSA_SIGN].digest = EVP_dss1(); c->pkeys[SSL_PKEY_DSA_SIGN].digest = EVP_sha1();
#endif #endif
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
if (!c->pkeys[SSL_PKEY_RSA_SIGN].digest) if (!c->pkeys[SSL_PKEY_RSA_SIGN].digest)
...@@ -3066,7 +3066,7 @@ int tls1_process_sigalgs(SSL *s, const unsigned char *data, int dsize) ...@@ -3066,7 +3066,7 @@ int tls1_process_sigalgs(SSL *s, const unsigned char *data, int dsize)
#endif #endif
#ifndef OPENSSL_NO_ECDSA #ifndef OPENSSL_NO_ECDSA
if (!c->pkeys[SSL_PKEY_ECC].digest) if (!c->pkeys[SSL_PKEY_ECC].digest)
c->pkeys[SSL_PKEY_ECC].digest = EVP_ecdsa(); c->pkeys[SSL_PKEY_ECC].digest = EVP_sha1();
#endif #endif
return 1; return 1;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册