- RFC6725 deprecates RSAMD5: this DNSKEY algorithm is disabled.

git-svn-id: file:///svn/unbound/trunk@2753 be551aaa-1e26-0410-a405-d3ace91eadb9
This commit is contained in:
Wouter Wijngaards 2012-08-30 12:02:53 +00:00
parent 6280983293
commit 5e5e89b9f5
2 changed files with 7 additions and 9 deletions

View file

@ -1,3 +1,6 @@
30 August 2012: Wouter
- RFC6725 deprecates RSAMD5: this DNSKEY algorithm is disabled.
29 August 2012: Wouter
- Nicer comments outgoing-port-avoid, thanks Stu (bug #465).

View file

@ -152,13 +152,8 @@ dnskey_algo_id_is_supported(int id)
{
switch(id) {
case LDNS_RSAMD5:
#ifdef HAVE_FIPS_MODE
/* openssl can return if the system is in FIPS mode,
* which does not allow MD5 hashes for network traffic */
return !FIPS_mode();
#else
return 1;
#endif
/* RFC 6725 deprecates RSAMD5 */
return 0;
case LDNS_DSA:
case LDNS_DSA_NSEC3:
case LDNS_RSASHA1:
@ -621,8 +616,8 @@ dnskey_algo_id_is_supported(int id)
/* uses libNSS */
switch(id) {
case LDNS_RSAMD5:
/* disable MD5 support if FIPS mode is enabled in libnss */
return !PK11_IsFIPS();
/* RFC 6725 deprecates RSAMD5 */
return 0;
case LDNS_DSA:
case LDNS_DSA_NSEC3:
case LDNS_RSASHA1: