On Tue, 2017-10-03 at 08:23 +0100, Matt Caswell wrote:
> > 1.2. This also opens the path to stronger key derivation (PBKDF2)
> > 2. During decryption, if no header block is present, and no message
> >    digest was specified, the default digest SHOULD be MD5.
> Should it? What about compatibility with OpenSSL 1.1.0? We cannot
> make
> breaking changes in 1.1.1, so it has to be compatible with 1.1.0.

Yeah, the ship has sailed. SHA-256 should be used by default as in

