+30 August 2012: Wouter
+ - RFC6725 deprecates RSAMD5: this DNSKEY algorithm is disabled.
+
29 August 2012: Wouter
- Nicer comments outgoing-port-avoid, thanks Stu (bug #465).
{
switch(id) {
case LDNS_RSAMD5:
-#ifdef HAVE_FIPS_MODE
- /* openssl can return if the system is in FIPS mode,
- * which does not allow MD5 hashes for network traffic */
- return !FIPS_mode();
-#else
- return 1;
-#endif
+ /* RFC 6725 deprecates RSAMD5 */
+ return 0;
case LDNS_DSA:
case LDNS_DSA_NSEC3:
case LDNS_RSASHA1:
/* uses libNSS */
switch(id) {
case LDNS_RSAMD5:
- /* disable MD5 support if FIPS mode is enabled in libnss */
- return !PK11_IsFIPS();
+ /* RFC 6725 deprecates RSAMD5 */
+ return 0;
case LDNS_DSA:
case LDNS_DSA_NSEC3:
case LDNS_RSASHA1: