Remove support for MD2
No part of IKE/IPsec or X.509 uses MD2 anymore, so there really is no reason to still support it (unlike MD4 that is used in EAP-MSCHAPv2, MD5 that's used in EAP-MD5, or SHA-1 that's used for e.g. NAT-D hashes). It caused test vectors to fail on systems where OpenSSL is built with MD2 support but has it disabled at runtime.
This commit is contained in:
@@ -94,7 +94,7 @@
|
||||
0x01 "PKCS"
|
||||
0x01 "PKCS-1"
|
||||
0x01 "rsaEncryption" OID_RSA_ENCRYPTION
|
||||
0x02 "md2WithRSAEncryption" OID_MD2_WITH_RSA
|
||||
0x02 "md2WithRSAEncryption"
|
||||
0x04 "md5WithRSAEncryption" OID_MD5_WITH_RSA
|
||||
0x05 "sha-1WithRSAEncryption" OID_SHA1_WITH_RSA
|
||||
0x07 "id-RSAES-OAEP" OID_RSAES_OAEP
|
||||
@@ -148,7 +148,7 @@
|
||||
0x05 "secretBag"
|
||||
0x06 "safeContentsBag"
|
||||
0x02 "digestAlgorithm"
|
||||
0x02 "md2" OID_MD2
|
||||
0x02 "md2"
|
||||
0x05 "md5" OID_MD5
|
||||
0x07 "hmacWithSHA1" OID_HMAC_SHA1
|
||||
0x08 "hmacWithSHA224" OID_HMAC_SHA224
|
||||
|
||||
Reference in New Issue
Block a user