summaryrefslogtreecommitdiffstats
path: root/ssl/ssl_cert.c
diff options
context:
space:
mode:
authorDr. Stephen Henson <steve@openssl.org>2014-04-05 13:39:35 +0100
committerDr. Stephen Henson <steve@openssl.org>2014-04-05 13:39:35 +0100
commitf8dd55bb5b1ed9fe7e1a3974329fdb4adbd786de (patch)
treed30839ff88a1d653f22570007c8918411fd89fc8 /ssl/ssl_cert.c
parentb7e46a9bce052d2d5b134bdfe0b5e34c90e000d6 (diff)
For more than 160 bits of security disable SHA1 HMAC
Diffstat (limited to 'ssl/ssl_cert.c')
-rw-r--r--ssl/ssl_cert.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/ssl/ssl_cert.c b/ssl/ssl_cert.c
index d56b2c5dd5..385d25f3f1 100644
--- a/ssl/ssl_cert.c
+++ b/ssl/ssl_cert.c
@@ -1411,6 +1411,9 @@ static int ssl_security_default_callback(SSL *s, SSL_CTX *ctx, int op, int bits,
/* No MD5 mac ciphersuites */
if (c->algorithm_mac & SSL_MD5)
return 0;
+ /* SHA1 HMAC is 160 bits of security */
+ if (minbits > 160 && c->algorithm_mac & SSL_SHA1)
+ return 0;
/* Level 2: no RC4 */
if (level >= 2 && c->algorithm_enc == SSL_RC4)
return 0;