We keep MD5 enabled for now as we need it for TLS 1.0/1.1. Once we remove that we can reconsider (although, it's also needed for EAP-MD5 and since MD4 is disabled as well, which means EAP-MSCHAPv2 won't be available, we'd be left with only EAP-GTC for simple username/password authentication, which nobody else supports).