[openssl.org #2472] req command silently ignores digest specifier when using EC signatures (0.9.8 only)

2014-08-12 Thread Rich Salz via RT
And, perhaps the least desireable fix: not going to fix 0.9.8 -- Rich Salz, OpenSSL dev team; rs...@openssl.org __ OpenSSL Project http://www.openssl.org Development Mailing List

[openssl.org #2472] req command silently ignores digest specifier when using EC signatures (0.9.8 only)

2011-03-18 Thread Nicko van Someren via RT
NOTE: This bug represents a potential security vulnerability, albeit a minor one. When using the 'req' command to construct a new x509 certificate using an elliptic curve signature algorithm, the digest specifier is SILENTLY ignored. Thus we get the following output OpenSSL version