]> git.ipfire.org Git - thirdparty/gnutls.git/commitdiff
_gnutls_pkcs_generate_key: use HMAC-SHA256 for PBKDF2
authorDaiki Ueno <ueno@gnu.org>
Tue, 21 Dec 2021 14:17:55 +0000 (15:17 +0100)
committerDaiki Ueno <ueno@gnu.org>
Fri, 7 Jan 2022 16:45:14 +0000 (17:45 +0100)
Signed-off-by: Daiki Ueno <ueno@gnu.org>
lib/x509/pkcs7-crypt.c

index c1e7bef21cd6730ccd4a1e5a50d3e334a4511adb..e714861bfe7aa42cbc08ab1cccf28556a0cfb6e6 100644 (file)
@@ -1576,7 +1576,7 @@ _gnutls_pkcs_generate_key(schema_id schema,
                         p->schema == PBES2_GOST28147_89_CPD)
                        kdf_params->mac = GNUTLS_MAC_GOSTR_94;
                else
-                       kdf_params->mac = GNUTLS_MAC_SHA1;
+                       kdf_params->mac = GNUTLS_MAC_SHA256;
                ret = _gnutls_pbes2_string_to_key(pass_len, password,
                                                  kdf_params,
                                                  kdf_params->key_size,