sp signingAlg and digestAlg defaults and setting explicit values

Paul B. Henson henson at acm.org
Mon Aug 19 21:54:16 UTC 2024


On 8/19/2024 12:56 PM, Cantor, Scott wrote:
> I do see one code path in a library that's falling back to signing
> with SHA-1 instead of conditionally using SHA-2 if OpenSSL supports
> it. There are two code paths in the file and one is different from
> the other, and I suspect that's a bug.

Thanks for checking; I opened issue SSPCPP-992 to track this.

> I'm probably going to be considering a rather artifical bump to 3.5.0
> to do some library cleanup work, that would be a good time to "fix" a
> broken default without doing it in a patch.

Cool, it would be great if this could be resolved in a release to avoid 
having to hardcode a specific option. My OCD would be really happy with 
you if you managed to pull in the packaging issue SSPCPP-991 fix to that 
as well :).

Thanks again…


More information about the users mailing list