Re: [RFC] enc utility & under-documented behavior changes: improving backward compatibility

"Robin H. Johnson" <[email protected]> Tue, 3 Oct 2017 17:51:20 +0000
Newsgroups gmane.comp.encryption.openssl.devel
Message-ID <[email protected]>
On Tue, Oct 03, 2017 at 09:45:43AM +0200, Tomas Mraz wrote:
> On Tue, 2017-10-03 at 08:23 +0100, Matt Caswell wrote:
> > 
> > > 1.2. This also opens the path to stronger key derivation (PBKDF2)
> > > 2. During decryption, if no header block is present, and no message
> > >    digest was specified, the default digest SHOULD be MD5.
> > 
> > Should it? What about compatibility with OpenSSL 1.1.0? We cannot
> > make
> > breaking changes in 1.1.1, so it has to be compatible with 1.1.0.
> Yeah, the ship has sailed. SHA-256 should be used by default as in
> 1.1.0.
It's a breaking change from 1.0.

At the very least, it should be added to the big notes:
https://www.openssl.org/news/openssl-1.1.0-notes.html
(this was in fact the first place I looked when my data was broken,
there was nothing about the enc tool here).

-- 
Robin Hugh Johnson
Gentoo Linux: Dev, Infra Lead, Foundation Asst. Treasurer
E-Mail   : [email protected]
GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85
GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
signature.asc (application/pgp-signature, 1.1 KB)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: Robbat2 @ Orbis-Terrarum Networks - The text below is a digital signature. If it doesn't make any sense to you, ignore it.

iQKTBAEBCgB9FiEEveu2pS8Vb98xaNkRGTlfI8WIJsQFAlnTzhdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEJE
RUJCNkE1MkYxNTZGREYzMTY4RDkxMTE5Mzk1RjIzQzU4ODI2QzQACgkQGTlfI8WI
JsTyAQ//S2DWOksuAW3luX7W+SLzS+KL+ApBortrgfkR4mlAI1lvXSvW7XmO7yBP
HDJi7+loxINV/Dq6OnOGRdBteJmOkDAF6MhqdMoKcv2viiUpmPTHPQu/GoBQJn5H
z+OnT1gQse7pxl5nWgy2bnYi05G74WyK1WVH4RNEo5FxJBzC3azIVf5Pj0Ygbfdd
lUmQTYf7E4JrR6qEKXeSzCExM93hSYnQ3MCdwQnLnQ5DeIZu4gb1aFs7546oYpFr
c0PyRQEHAfRF1xU+7jS9eRr+hnqfsrA9+yVzTYUo1u9DWM7o+3pJOJAT3ph8asvo
HqEkxzKstSYErEb+BtVe8LaAIg9p8Voct9NgdvArpPlx1mDTCCIVIUYQOhQYCJTR
8MStxvWs5XCl5eo0PIZtkw/PKUZOjZtGrYa0W8QoxZNJZQGXJyy/yzsKcT/Wt8xw
0+YWIA5fysDqY/Af36830EPTXEsM+YZhR1l6chxCFLUjg3x+6P1weSGrk8HIFYiL
W1/5SAOApfvSbGAVA80S2kIPTnnAhHBmASe5+/ZrDdMjC+N3UqYp1qNotqJm1sIb
KkEyDeDYuoHC3aXgqe9U4yfcVTnofEe/KNA7LEYuGXt8Y3vGUcHZZwD5+bGSEWAw
vItX9t3DU6dnnXU0tZte0Qm33QQngNY7ZRHhtXV9kwQ56Q7BWLw=
=QaXp
-----END PGP SIGNATURE-----