The SHA256 is not a mandatory digest for DSA.
authorTomas Mraz <tmraz@fedoraproject.org>
Mon, 27 May 2019 14:52:03 +0000 (16:52 +0200)
committerTomas Mraz <tmraz@fedoraproject.org>
Tue, 28 May 2019 15:22:14 +0000 (17:22 +0200)
commit871c675b8592261abb7de294b40f2c6f7311fa58
treef274104e92279bee9089be9a2e5a40075a5b0cc7
parentb29cd8b57f0764c413e40b42f077a2de74b87f13
The SHA256 is not a mandatory digest for DSA.

The #7408 implemented mandatory digest checking in TLS.
However this broke compatibility of DSS support with GnuTLS
which supports only SHA1 with DSS.

There is no reason why SHA256 would be a mandatory digest
for DSA as other digests in SHA family can be used as well.

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/9015)

(cherry picked from commit cd4c83b52423008391b50abcccf18a7d8fcce03b)
crypto/dsa/dsa_ameth.c