aboutsummaryrefslogtreecommitdiffstats
path: root/lib/eldap
diff options
context:
space:
mode:
authorPéter Dimitrov <[email protected]>2018-10-03 13:33:39 +0200
committerPéter Dimitrov <[email protected]>2018-10-15 10:21:23 +0200
commitd5ffd9ddd6edd21e190bb61547c835892e917a6c (patch)
tree5c3f02d2024f038f75b981aba424c310cd1e482b /lib/eldap
parent3b87e676e0b673afbd8398099b607702ca52ef7c (diff)
downloadotp-d5ffd9ddd6edd21e190bb61547c835892e917a6c.tar.gz
otp-d5ffd9ddd6edd21e190bb61547c835892e917a6c.tar.bz2
otp-d5ffd9ddd6edd21e190bb61547c835892e917a6c.zip
eldap: Update default hash algorithm in FT
Update default hash algorithm (md5 -> sha1) used for generating the server and CA certificates. Default support for md5 has been removed for TLS 1.2 and OTP-15248 introduced a check for the whole {hash, signature} algorithm pair as defined by RFC5246. Change-Id: I964914914f522c10ef11c8c7c72bb9e4a0c38010
Diffstat (limited to 'lib/eldap')
-rw-r--r--lib/eldap/test/make_certs.erl4
1 files changed, 2 insertions, 2 deletions
diff --git a/lib/eldap/test/make_certs.erl b/lib/eldap/test/make_certs.erl
index cfa43289e1..e8a13ae113 100644
--- a/lib/eldap/test/make_certs.erl
+++ b/lib/eldap/test/make_certs.erl
@@ -348,7 +348,7 @@ req_cnf(C) ->
"default_bits = ", integer_to_list(C#config.default_bits), "\n"
"RANDFILE = $ROOTDIR/RAND\n"
"encrypt_key = no\n"
- "default_md = md5\n"
+ "default_md = sha1\n"
"#string_mask = pkix\n"
"x509_extensions = ca_ext\n"
"prompt = no\n"
@@ -394,7 +394,7 @@ ca_cnf(C) ->
["crl_extensions = crl_ext\n" || C#config.v2_crls],
"unique_subject = no\n"
"default_days = 3600\n"
- "default_md = md5\n"
+ "default_md = sha1\n"
"preserve = no\n"
"policy = policy_match\n"
"\n"