[#76442] [Ruby trunk Feature#11741] Migrate Ruby to Git from Subversion — naruse@...
Issue #11741 has been updated by Yui NARUSE.
3 messages
2016/07/19
[#76515] [Ruby trunk Bug#12610] webrick: protect from httpoxy — nagachika00@...
Issue #12610 has been updated by Tomoyuki Chikanaga.
3 messages
2016/07/22
[ruby-core:76245] [Ruby trunk Bug#9154][Closed] Support for OpenSSL with MD5 disabled for certificate verification
From:
k@...
Date:
2016-07-03 07:01:54 UTC
List:
ruby-core #76245
Issue #9154 has been updated by Kazuki Yamaguchi.
Status changed from Open to Closed
Backport deleted (1.9.3: REQUIRED, 2.0.0: REQUIRED)
Closing this as it is already fixed.
----------------------------------------
Bug #9154: Support for OpenSSL with MD5 disabled for certificate verification
https://bugs.ruby-lang.org/issues/9154#change-59484
* Author: Vit Ondruch
* Status: Closed
* Priority: Normal
* Assignee: openssl
* ruby -v: ruby 2.0.0p247 (2013-06-27) [x86_64-linux]
* Backport:
----------------------------------------
=begin
In Fedora Rawhide, there was disable support for verification of certificate, CRL, and OCSP signatures using MD5 in OpenSSL [1, 2], therefore I observe following test errors:
7) Error:
test_sign_and_verify(OpenSSL::TestX509Request):
OpenSSL::X509::RequestError: unknown message digest algorithm
/builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509req.rb:111:in `verify'
/builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509req.rb:111:in `test_sign_and_verify'
8) Error:
test_sign_and_verify(OpenSSL::TestX509Certificate):
OpenSSL::X509::CertificateError: unknown message digest algorithm
/builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509cert.rb:140:in `verify'
/builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509cert.rb:140:in `test_sign_and_verify'
I was suggested by OpenSSL maintainer, that MD5 is obsolete and for modernization, it would be more useful to test SHA256 instead of MD5 for example. Any chance to make this test could pass out of the box and support more modern hashing algorithms?
[1] http://pkgs.fedoraproject.org/cgit/openssl.git/commit/?id=dcd0fb1ec9e2ef9bace5473cb3924a8d867ce84b
[2] http://pkgs.fedoraproject.org/cgit/openssl.git/commit/?id=9caf868063fd085ed4b2246f5f8dde91873d1c15
=end
--
https://bugs.ruby-lang.org/
Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>