ikev2: Don't use SHA-1 for RFC 7427 signature authentication

RFC 8247 demoted it to MUST NOT.

References #2427.
This commit is contained in:
Tobias Brunner
2017-11-08 16:47:24 +01:00
parent 76c58498ef
commit 43b59d1323
3 changed files with 5 additions and 7 deletions
@@ -156,14 +156,12 @@ static array_t *select_signature_schemes(keymat_v2_t *keymat,
}
enumerator->destroy(enumerator);
/* for RSA we tried at least SHA-512, also try other schemes down to
* what we'd use with classic authentication */
/* for RSA we tried at least SHA-512, also try other schemes */
if (key_type == KEY_RSA)
{
signature_scheme_t schemes[] = {
SIGN_RSA_EMSA_PKCS1_SHA2_384,
SIGN_RSA_EMSA_PKCS1_SHA2_256,
SIGN_RSA_EMSA_PKCS1_SHA1,
}, contained;
bool found;
int i, j;