Package: gnupg2 / 2.2.12-1+deb10u1

update-defaults/gpg-Prefer-SHA-512-and-SHA-384-in-personal-digest.patch Patch series | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Date: Wed, 3 Jan 2018 12:34:26 -0500
Subject: gpg: Prefer SHA-512 and SHA-384 in personal-digest-preferences.

* g10/keygen.c (keygen_set_std_prefs): prefer SHA-512
and SHA-384 by default.

--

In 8ede3ae29a39641a2f98ad9a4cf61ea99085a892, upstream changed the
defaults for --default-preference-list to advertise a preference for
SHA-512, without touching --personal-digest-preferences.  This makes
the same change for --personal-digest-preferences, since every modern
OpenPGP library supports them all.

Signed-off-by: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
---
 g10/keygen.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/g10/keygen.c b/g10/keygen.c
index 492c65f..a8333b0 100644
--- a/g10/keygen.c
+++ b/g10/keygen.c
@@ -386,16 +386,16 @@ keygen_set_std_prefs (const char *string,int personal)
             if (personal)
               {
                 /* The default internal hash algo order is:
-                 *  SHA-256, SHA-384, SHA-512, SHA-224, SHA-1.
+                 *  SHA-512, SHA-384, SHA-256, SHA-224, SHA-1.
                  */
-                if (!openpgp_md_test_algo (DIGEST_ALGO_SHA256))
-                  strcat (dummy_string, "H8 ");
+                if (!openpgp_md_test_algo (DIGEST_ALGO_SHA512))
+                  strcat (dummy_string, "H10 ");
 
                 if (!openpgp_md_test_algo (DIGEST_ALGO_SHA384))
                   strcat (dummy_string, "H9 ");
 
-                if (!openpgp_md_test_algo (DIGEST_ALGO_SHA512))
-                  strcat (dummy_string, "H10 ");
+                if (!openpgp_md_test_algo (DIGEST_ALGO_SHA256))
+                  strcat (dummy_string, "H8 ");
               }
             else
               {