On Fri, 2013-12-20 at 16:46:42 -0500, Mikhail T. wrote:
> Thinking more about the MD2, I'd say, FreeBSD should not have removed the 
> algorithm.
> 
> Although no longer deemed sufficiently secure, it is still in use and people
> using it on FreeBSD-8.x and 9.x today may wish to continue doing so after
> upgrading to 10.x
> 
> In the old "Mechanism vs. Policy" debate
> <http://en.wikipedia.org/wiki/Separation_of_mechanism_and_policy> we erred on
> the side of policy and it does not seem right... Whether or not to use MD2 is
> (or should be) left up to the users of FreeBSD. Even if OpenSSL no longer
> provides it, libmd should continue to.
> 
> In other words, /if you like your digest algorithm, you can keep it/. Yours,

Seconded. What should people use if some of their old data is using MD2
for verification? How can they now easily check that their data (from
tape or whatever) still matches the fingerprint?

Cheers,
Uli
_______________________________________________
freebsd-current@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscr...@freebsd.org"

Reply via email to