pkcs7: mention MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES in pkcs7.h documentation

Signed-off-by: Valerio Setti <[email protected]>
This commit is contained in:
Valerio Setti
2026-06-22 11:46:29 +02:00
parent 0b556f5a2d
commit 4008c7f811
+5 -3
View File
@@ -32,9 +32,11 @@
* - The RFC allows for the signed Data type to contain contentInfo. This
* implementation assumes the type is DATA and the content is empty.
* - The RFC doesn't put any constrain on the hash algorithm to be used, but
* this implementation rejects weak hash algorithms (i.e. RIPEMD160, MD5,
* SHA-1, SHA-224, SHA3-224). In general accepted hash and PK algorithms are
* the ones belonging to `mbedtls_x509_crt_profile_default`.
* this implementation by default rejects weak hash algorithms (i.e. RIPEMD160,
* MD5, SHA-1, SHA-224, SHA3-224). In general accepted hash and PK algorithms
* are the ones belonging to `mbedtls_x509_crt_profile_default`.
* MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES can be enabled to remove the limitation
* on weak hash algorithms.
*/
#ifndef MBEDTLS_PKCS7_H