Home GnuPG

cipher: Reject SHA-1 for hash+sign/verify when FIPS enabled.

Description

cipher: Reject SHA-1 for hash+sign/verify when FIPS enabled.

* cipher/pubkey.c (_gcry_pk_sign_md): Reject SHA-1 when FIPS.
(_gcry_pk_verify_md): Likewise.
  • GnuPG-bug-id: T5665
  • Signed-off-by: NIIBE Yutaka <gniibe@fsij.org>

Details

Provenance
gniibeAuthored on Oct 20 2021, 5:09 AM
Parents
rC8f31f652d453: doc: Add entries for hash+sign functions.
Branches
Unknown
Tags
Unknown
Tasks
T5665: libgcrypt : Restrict message digest use for FIPS 140-3