[tls] Avoid dragging in MD5+SHA1 algorithm unconditionally

Use a version check to gate the selection of md5_sha1_algorithm as the
signature digest algorithm, since this can be optimised out at build
time if the minimum version has been configured to be higher than TLS
version 1.1.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-18 16:17:15 +01:00
parent 8402079a17
commit 6deb51d66c
+8 -1
View File
@@ -2852,14 +2852,21 @@ static int tls_verify_signature ( struct tls_connection *tls,
}
/* Identify signature and hash algorithm */
if ( dsig.sig_hash ) {
if ( tls_version ( tls, TLS_VERSION_TLS_1_2 ) ) {
/* TLSv1.2 and above use explicit algorithm identifiers */
assert ( dsig.sig_hash != NULL );
sig_hash = tls_find_signature_hash ( *dsig.sig_hash );
if ( ! sig_hash ) {
DBGC ( tls, "TLS %p unsupported signature hash "
"%#04x\n", tls, ntohs ( *dsig.sig_hash ) );
return -ENOTSUP_SIG_HASH;
}
} else {
/* TLSv1.1 and below use fixed algorithms */
assert ( dsig.sig_hash == NULL );
sig_hash = &tmp;
memset ( sig_hash, 0, sizeof ( *sig_hash ) );
sig_hash->pubkey = suite->pubkey;