summaryrefslogtreecommitdiffstats
path: root/lib/libssl/ssl_sigalgs.c
diff options
context:
space:
mode:
authorbeck <beck@openbsd.org>2019-01-24 00:07:58 +0000
committerbeck <beck@openbsd.org>2019-01-24 00:07:58 +0000
commitdec63d9faba0224ad77d9164222335591a724125 (patch)
treea8cae2ba41a1a06644c00f9c2d5d69bab79b09fd /lib/libssl/ssl_sigalgs.c
parentgdt64 is only used by locore0 during the gut-wrenching 32-bit bring-up, so (diff)
downloadwireguard-openbsd-dec63d9faba0224ad77d9164222335591a724125.tar.xz
wireguard-openbsd-dec63d9faba0224ad77d9164222335591a724125.zip
Remove SHA224 based sigalgs from use in TLS 1.2 as SHA224 is deprecated.
Remove GOST based sigalgs from TLS 1.2 since they don't work with TLS 1.2. ok jsing@
Diffstat (limited to 'lib/libssl/ssl_sigalgs.c')
-rw-r--r--lib/libssl/ssl_sigalgs.c7
1 files changed, 1 insertions, 6 deletions
diff --git a/lib/libssl/ssl_sigalgs.c b/lib/libssl/ssl_sigalgs.c
index 76cb441b075..fdea93e1b05 100644
--- a/lib/libssl/ssl_sigalgs.c
+++ b/lib/libssl/ssl_sigalgs.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: ssl_sigalgs.c,v 1.15 2019/01/23 23:47:13 beck Exp $ */
+/* $OpenBSD: ssl_sigalgs.c,v 1.16 2019/01/24 00:07:58 beck Exp $ */
/*
* Copyright (c) 2018-2019 Bob Beck <beck@openbsd.org>
*
@@ -182,17 +182,12 @@ uint16_t tls12_sigalgs[] = {
SIGALG_RSA_PSS_RSAE_SHA512,
SIGALG_RSA_PKCS1_SHA512,
SIGALG_ECDSA_SECP521R1_SHA512,
- SIGALG_GOSTR12_512_STREEBOG_512,
SIGALG_RSA_PSS_RSAE_SHA384,
SIGALG_RSA_PKCS1_SHA384,
SIGALG_ECDSA_SECP384R1_SHA384,
SIGALG_RSA_PSS_RSAE_SHA256,
SIGALG_RSA_PKCS1_SHA256,
SIGALG_ECDSA_SECP256R1_SHA256,
- SIGALG_GOSTR12_256_STREEBOG_256,
- SIGALG_GOSTR01_GOST94,
- SIGALG_RSA_PKCS1_SHA224,
- SIGALG_ECDSA_SECP224R1_SHA224,
SIGALG_RSA_PKCS1_SHA1, /* XXX */
SIGALG_ECDSA_SHA1, /* XXX */
};