ovs-pki: Use SHA-512 instead of SHA-1 as message digest.
authorBen Pfaff <blp@ovn.org>
Sat, 2 Jul 2016 01:05:40 +0000 (18:05 -0700)
committerBen Pfaff <blp@ovn.org>
Fri, 22 Jul 2016 20:26:11 +0000 (13:26 -0700)
commit29dd784d7634e98f16728343df2e57e9fd9d26f2
tree9d3f1c1918065ad5a1a9511f78cf32016479c2c2
parentf7525086194e05f88cc9d20fe941e22d2eb598bc
ovs-pki: Use SHA-512 instead of SHA-1 as message digest.

The upcoming OpenSSL 1.1.0 release disables use of SHA-1, which breaks the
OVS unit tests, which use SHA-1.  We last tried to switch to SHA-512 in
2014 with commit 9ff33ca75e9fcc ("ovs-pki: Use SHA-512 instead of MD5 as
message digest."), but we had to downgrade to SHA-1 in commit 4a1f9610682d
("ovs-pki: Use SHA-1 instead of SHA-512 as message digest.") because
XenServer did not support SHA-512.  It has been a few years, so let's try
again.

CC: 828478@bugs.debian.org
Reported-at: https://bugs.debian.org/828478
Reported-by: Kurt Roeckx <kurt@roeckx.be>
Signed-off-by: Ben Pfaff <blp@ovn.org>
Acked-by: Ryan Moats <rmoats@us.ibm.com>
NEWS
utilities/ovs-pki.in