Subject: misc/26838: exmaples/openssl/ssl.cnf has an insecure default
To: None <>
From: None <>
List: netbsd-bugs
Date: 09/02/2004 21:40:39
>Number: 26838
>Category: misc
>Synopsis: exmaples/openssl/ssl.cnf has an insecure default
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: misc-bug-people
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Fri Sep 03 01:41:00 UTC 2004
>Originator: Steven M. Bellovin
>Release: NetBSD 2.0_BETA
AT&T Labs Research
System: NetBSD 2.0_BETA NetBSD 2.0_BETA (BERKSHIRE) #2: Thu Aug 26 17:35:54 EDT 2004 i386
Architecture: i386
Machine: i386
/usr/share/examples/openssl/openssl.cnf has a line
default_md = md5
This isn't very secure any more; it should use sha1.
see above
Change the line to
default_md = sha1