mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-01-05 06:19:35 -05:00
- RFC6725 deprecates RSAMD5: this DNSKEY algorithm is disabled.
git-svn-id: file:///svn/unbound/trunk@2753 be551aaa-1e26-0410-a405-d3ace91eadb9
This commit is contained in:
parent
6280983293
commit
5e5e89b9f5
2 changed files with 7 additions and 9 deletions
|
|
@ -1,3 +1,6 @@
|
|||
30 August 2012: Wouter
|
||||
- RFC6725 deprecates RSAMD5: this DNSKEY algorithm is disabled.
|
||||
|
||||
29 August 2012: Wouter
|
||||
- Nicer comments outgoing-port-avoid, thanks Stu (bug #465).
|
||||
|
||||
|
|
|
|||
|
|
@ -152,13 +152,8 @@ dnskey_algo_id_is_supported(int id)
|
|||
{
|
||||
switch(id) {
|
||||
case LDNS_RSAMD5:
|
||||
#ifdef HAVE_FIPS_MODE
|
||||
/* openssl can return if the system is in FIPS mode,
|
||||
* which does not allow MD5 hashes for network traffic */
|
||||
return !FIPS_mode();
|
||||
#else
|
||||
return 1;
|
||||
#endif
|
||||
/* RFC 6725 deprecates RSAMD5 */
|
||||
return 0;
|
||||
case LDNS_DSA:
|
||||
case LDNS_DSA_NSEC3:
|
||||
case LDNS_RSASHA1:
|
||||
|
|
@ -621,8 +616,8 @@ dnskey_algo_id_is_supported(int id)
|
|||
/* uses libNSS */
|
||||
switch(id) {
|
||||
case LDNS_RSAMD5:
|
||||
/* disable MD5 support if FIPS mode is enabled in libnss */
|
||||
return !PK11_IsFIPS();
|
||||
/* RFC 6725 deprecates RSAMD5 */
|
||||
return 0;
|
||||
case LDNS_DSA:
|
||||
case LDNS_DSA_NSEC3:
|
||||
case LDNS_RSASHA1:
|
||||
|
|
|
|||
Loading…
Reference in a new issue