From 671ab30bb97f4c2f8f2e37b40cd8456b45836c74 Mon Sep 17 00:00:00 2001 From: jsg <> Date: Sat, 19 Jan 2019 21:17:05 +0000 Subject: change the default digest used by openssl x509 -fingerprint openssl crl -fingerprint from sha1 to sha256 ok jsing@ --- src/usr.bin/openssl/crl.c | 4 ++-- src/usr.bin/openssl/x509.c | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) (limited to 'src') diff --git a/src/usr.bin/openssl/crl.c b/src/usr.bin/openssl/crl.c index 645b16ea54..cb1c18fa40 100644 --- a/src/usr.bin/openssl/crl.c +++ b/src/usr.bin/openssl/crl.c @@ -1,4 +1,4 @@ -/* $OpenBSD: crl.c,v 1.11 2018/02/07 05:47:55 jsing Exp $ */ +/* $OpenBSD: crl.c,v 1.12 2019/01/19 21:17:05 jsg Exp $ */ /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * @@ -243,7 +243,7 @@ crl_main(int argc, char **argv) } } - digest = EVP_sha1(); + digest = EVP_sha256(); memset(&crl_config, 0, sizeof(crl_config)); crl_config.informat = FORMAT_PEM; diff --git a/src/usr.bin/openssl/x509.c b/src/usr.bin/openssl/x509.c index 84aeed3c07..b25a7c828c 100644 --- a/src/usr.bin/openssl/x509.c +++ b/src/usr.bin/openssl/x509.c @@ -1,4 +1,4 @@ -/* $OpenBSD: x509.c,v 1.16 2018/02/07 05:47:55 jsing Exp $ */ +/* $OpenBSD: x509.c,v 1.17 2019/01/19 21:17:05 jsg Exp $ */ /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * @@ -788,7 +788,7 @@ x509_main(int argc, char **argv) const EVP_MD *fdig = digest; if (!fdig) - fdig = EVP_sha1(); + fdig = EVP_sha256(); if (!X509_digest(x, fdig, md, &n)) { BIO_printf(bio_err, "out of memory\n"); -- cgit v1.2.3-55-g6feb