Skip to content

Add option to specify OpenSSL digest type#3

Open
mandoonandy wants to merge 2 commits intoclinta:masterfrom
mandoonandy:master
Open

Add option to specify OpenSSL digest type#3
mandoonandy wants to merge 2 commits intoclinta:masterfrom
mandoonandy:master

Conversation

@mandoonandy
Copy link
Contributor

OpenSSL have changed the default key from MD5 to SHA256. This is part of the deprecation of MD5.

Any geliUnlocker configuration built using MD5 will now fail with an error during the openssl decryption.

Add an option to specify the openssl key digest. If the option is not specified in rc.conf, then the option is ignored.

unlockgeli_cpool_key_digest="md5"

mandoonandy and others added 2 commits April 30, 2020 15:06
OpenSSL has deprecated MD5 key digests. The default digest was
MD5. To avoid regenerating keys that use MD5 this option allows
users to specify the digest type.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant