From owner-freebsd-current@FreeBSD.ORG Fri Dec 20 18:38:13 2013 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 5C4AC1AC for ; Fri, 20 Dec 2013 18:38:13 +0000 (UTC) Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id E90EE1EA8 for ; Fri, 20 Dec 2013 18:38:12 +0000 (UTC) Received: from [192.168.0.100] ([87.139.233.65]) by mail.gmx.com (mrgmx102) with ESMTPSA (Nemesis) id 0M6874-1Valew2Ee2-00yADm for ; Fri, 20 Dec 2013 19:38:04 +0100 Message-ID: <52B48E8C.5070804@gmx.de> Date: Fri, 20 Dec 2013 19:38:04 +0100 From: olli hauer User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:24.0) Gecko/20100101 Thunderbird/24.2.0 MIME-Version: 1.0 To: Current FreeBSD Subject: Re: md2 on current and 10. References: <52B392D9.4030507@aldan.algebra.com> <52B483D7.7080302@gmx.de> <52B486AD.7080102@aldan.algebra.com> In-Reply-To: <52B486AD.7080102@aldan.algebra.com> X-Enigmail-Version: 1.6 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Provags-ID: V03:K0:B6xuEsFfTuo3dhW61WfF/aZDMbE6KOC0/K/+QTUOWpMh/Dpx2kL U6yUbTwD9zpuUVd93FCE9RBBseSAi5gJ2nyAsyt4W+W2j7rM2YviPGob8KSUiqkIQqk5K1u /qr9tmQSKOJUEYcHioaDmsMdi7lkOhIcrdvAMbCzLXLvCZ+90aH87PHuboQYAUp7cMV8kGJ bvA6cle+roDr3BFPS/c/g== Cc: "Mikhail T." X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Dec 2013 18:38:13 -0000 On 2013-12-20 19:04, Mikhail T. wrote: > On 20.12.2013 12:52, olli hauer wrote: >> Hm the config script tests for md2 and sha1 ... >> What happens if md2 support is removed from the code? > Yes, the md2 can be removed from the set of digests made available by the port > -- that's not a problem. > > What I wanted to know, was why? Maybe, the header files should've been replaced > with ones containing an #error (like malloc.h was)... Oh well... > > -mi md2 was deprecated in 2009 by the openssl project http://cvs.openssl.org/chngview?cn=18381 CVE-2009-2409 As fas as I know some Linux based projects have removed md2 from openssl-0.9.x in 2009. I have no answer why FreeBSD 8/9 has the old openssl-0.9.8y and md2 support was not removed. -- olli