Skip to content

Commit 4bb6895

Browse files
Zuulopenstack-gerrit
authored andcommitted
Merge "winrmlistener: use sha2 instead of insecure sha1"
2 parents 2b1770d + a373d55 commit 4bb6895

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

cloudbaseinit/utils/windows/cryptoapi.py

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -137,8 +137,10 @@ class CERT_KEY_CONTEXT(ctypes.Structure):
137137
CERT_KEY_PROV_INFO_PROP_ID = 2
138138
CERT_KEY_CONTEXT_PROP_ID = 5
139139

140+
# https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-wincrypt-crypt_algorithm_identifier
140141
szOID_PKIX_KP_SERVER_AUTH = b"1.3.6.1.5.5.7.3.1"
141142
szOID_RSA_SHA1RSA = b"1.2.840.113549.1.1.5"
143+
szOID_RSA_SHA256RSA = b"1.2.840.113549.1.1.11"
142144

143145
advapi32 = windll.advapi32
144146
crypt32 = windll.crypt32

cloudbaseinit/utils/windows/x509.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -195,7 +195,7 @@ def create_self_signed_cert(self, subject, validity_years=10,
195195
key_prov_info.dwFlags = 0
196196

197197
sign_alg = cryptoapi.CRYPT_ALGORITHM_IDENTIFIER()
198-
sign_alg.pszObjId = cryptoapi.szOID_RSA_SHA1RSA
198+
sign_alg.pszObjId = cryptoapi.szOID_RSA_SHA256RSA
199199

200200
start_time = cryptoapi.SYSTEMTIME()
201201
cryptoapi.GetSystemTime(ctypes.byref(start_time))

0 commit comments

Comments
 (0)