pkcs7: improve documentation and changelog for MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES

Signed-off-by: Valerio Setti <[email protected]>
This commit is contained in:
Valerio Setti
2026-06-22 11:46:29 +02:00
parent 4008c7f811
commit dfa6a1441e
2 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
Security
* PKCS7 now rejects weak hash algorithms (RIPEMD160, MD5, SHA-1, SHA-224,
SHA3-224) on signature verification. Build symbol
SHA3-224) on signature verification. The new configuration option
MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES allows to keep using weak hash
algorithms in PKCS7 for backward compatibility purposes.
+3 -3
View File
@@ -34,9 +34,9 @@
* - The RFC doesn't put any constrain on the hash algorithm to be used, but
* this implementation by default rejects weak hash algorithms (i.e. RIPEMD160,
* MD5, SHA-1, SHA-224, SHA3-224). In general accepted hash and PK algorithms
* are the ones belonging to `mbedtls_x509_crt_profile_default`.
* MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES can be enabled to remove the limitation
* on weak hash algorithms.
* are the ones belonging to ::mbedtls_x509_crt_profile_default.
* #MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES can be enabled to accept all
* supported hash algorithms.
*/
#ifndef MBEDTLS_PKCS7_H