diff options
author | Kurt Roeckx <kurt@roeckx.be> | 2020-01-02 23:25:27 +0100 |
---|---|---|
committer | Kurt Roeckx <kurt@roeckx.be> | 2020-02-05 22:04:37 +0100 |
commit | b744f915ca8bb37631909728dd2529289bda8438 (patch) | |
tree | e051ce8f2cf9a06de1a40d1c9b238dc33ba0d11f /NEWS | |
parent | 4d9e8c95544d7a86765e6a46951dbe17b801875a (diff) | |
download | openssl-new-b744f915ca8bb37631909728dd2529289bda8438.tar.gz |
Stop accepting certificates signed using SHA1 at security level 1
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
GH: #10786
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 4 |
1 files changed, 4 insertions, 0 deletions
@@ -7,6 +7,10 @@ Major changes between OpenSSL 1.1.1 and OpenSSL 3.0.0 [under development] + o X509 certificates signed using SHA1 are no longer allowed at security + level 1 or higher. The default security level for TLS is 1, so + certificates signed using SHA1 are by default no longer trusted to + authenticate servers or clients. o enable-crypto-mdebug and enable-crypto-mdebug-backtrace were mostly disabled; the project uses address sanitize/leak-detect instead. o Added OSSL_SERIALIZER, a generic serializer API. |