sp signingAlg and digestAlg defaults and setting explicit values
Paul B. Henson
henson at acm.org
Mon Aug 19 21:54:16 UTC 2024
On 8/19/2024 12:56 PM, Cantor, Scott wrote:
> I do see one code path in a library that's falling back to signing
> with SHA-1 instead of conditionally using SHA-2 if OpenSSL supports
> it. There are two code paths in the file and one is different from
> the other, and I suspect that's a bug.
Thanks for checking; I opened issue SSPCPP-992 to track this.
> I'm probably going to be considering a rather artifical bump to 3.5.0
> to do some library cleanup work, that would be a good time to "fix" a
> broken default without doing it in a patch.
Cool, it would be great if this could be resolved in a release to avoid
having to hardcode a specific option. My OCD would be really happy with
you if you managed to pull in the packaging issue SSPCPP-991 fix to that
as well :).
Thanks again…
More information about the users
mailing list