Comment 6 for bug 19835

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Thu, 23 Jun 2005 10:32:34 +0200
From: Christoph Martin <email address hidden>
To: <email address hidden>
Subject: [Fwd: [openssl.org #1128] [Fwd: Bug#314465: CA.pl and openssl.cnf
 default to insecure MD5 digest]]

--------------enig6DC41261DF035C1F4297DD86
Content-Type: multipart/mixed;
 boundary="------------030601030707060407020701"

This is a multi-part message in MIME format.
--------------030601030707060407020701
Content-Type: text/plain; charset=ISO-8859-15
Content-Transfer-Encoding: 7bit

--
============================================================================
Christoph Martin, EDV der Verwaltung, Uni-Mainz, Germany
 Internet-Mail: <email address hidden>
  Telefon: +49-6131-3926337
      Fax: +49-6131-3922856

--------------030601030707060407020701
Content-Type: message/rfc822;
 name="[openssl.org #1128] [Fwd: Bug#314465: CA.pl and openssl.cnf default to insecureMD5
 digest]"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline;
 filename="[openssl.org #1128] [Fwd: Bug#314465: CA.pl and openssl.cnf default to insecureMD5
 digest]"

Return-Path: <email address hidden>
Received: from mailgate2.zdv.Uni-Mainz.DE (mailgate2.zdv.Uni-Mainz.DE [134.93.178.130])
 by wintermute.verwaltung.uni-mainz.de (8.13.4/8.13.4/Debian-3) with ESMTP id j5N7Q617021122
 for <email address hidden>; Thu, 23 Jun 2005 09:26:06 +0200
Received: from exfront01.zdv.uni-mainz.de (exfront01.zdv.Uni-Mainz.DE [134.93.176.49])
 by mailgate2.zdv.Uni-Mainz.DE (Postfix) with ESMTP id 74C173000639
 for <email address hidden>; Thu, 23 Jun 2005 09:26:06 +0200 (CEST)
Received: from spamgate2.zdv.Uni-Mainz.DE ([134.93.177.66]) by exfront01.zdv.uni-mainz.de with
 Microsoft SMTPSVC(6.0.3790.211); Thu, 23 Jun 2005 09:26:06 +0200
Received: from mailgate1.zdv.Uni-Mainz.DE (mailgate1.zdv.Uni-Mainz.DE [134.93.178.129])
 by spamgate2.zdv.Uni-Mainz.DE (8.12.10/8.12.2) with ESMTP id j5N7Q1C8013565
 for <email address hidden>; Thu, 23 Jun 2005 09:26:01 +0200 (MEST)
Received: from serv01.aet.tu-cottbus.de (serv01.aet.TU-Cottbus.De [141.43.132.161])
 (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by mailgate1.zdv.Uni-Mainz.DE (Postfix) with ESMTP id 3FC433000FEC
 for <email address hidden>; Thu, 23 Jun 2005 09:26:01 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
 by serv01.aet.tu-cottbus.de (Postfix) with ESMTP id 9D6F82C5F;
 Thu, 23 Jun 2005 09:25:56 +0200 (METDST)
Received: by serv01.aet.tu-cottbus.de (Postfix, from userid 29999)
 id 8784A2C58; Thu, 23 Jun 2005 09:25:52 +0200 (METDST)
X-RT-Loop-Prevention: openssl.org
Message-Id: <email address hidden>
Subject: [openssl.org #1128] [Fwd: Bug#314465: CA.pl and openssl.cnf default to insecure MD5 digest]
In-Reply-To: <email address hidden>
Managed-BY: RT 2.0.15 (http://bestpractical.com/rt/)
From: "Nils Larsch via RT" <email address hidden>
RT-Ticket: openssl.org #1128
X-Mailer: Perl5 Mail::Internet v1.33
Reply-To: <email address hidden>
Precedence: bulk
RT-Originator: <email address hidden>
To: <email address hidden>
Cc: <email address hidden>
Sender: <email address hidden>
Date: Thu, 23 Jun 2005 09:25:52 +0200 (METDST)
X-Virus-Scanned: by amavisd 0.1
X-Virus-Scanned: by amavisd-new at uni-mainz.de
X-Spam-Level:
X-OriginalArrivalTime: 23 Jun 2005 07:26:06.0246 (UTC) FILETIME=[D1864460:01C577C4]
X-Virus-Scanned: by amavisd-new at uni-mainz.de
X-Spam-Status: No, hits=-2.313 required=5 tests=AWL,BAYES_00 version=3.0.3
X-Scanned-By: MIMEDefang 2.51 on 134.93.225.251
X-UID: 7143
X-Keywords: NonJunk

The default digest in 0.9.8 and the cvs head is SHA-1
(we didn't change 0.9.7 as we didn't want to break existing
implementations depending on the default digest being MD5).
About SHA-256 etc. : they are included in the soon to
appear 0.9.8.

Cheers,
Nils

--------------030601030707060407020701--

--------------enig6DC41261DF035C1F4297DD86
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCunOngeVih7XOVJcRAi17AJsEksYzZ0nFT677Y6K6SAmryZq9xgCfWvSv
25c5vyGB2cWTT4RvBowcpH0=
=lPpY
-----END PGP SIGNATURE-----

--------------enig6DC41261DF035C1F4297DD86--