DH.derive_key uses SHA1, which is deprecated
UnixJunkie opened this issue · 3 comments
UnixJunkie commented
As a European citizen, I would prefer RIPEMD160, but I am not a specialist of those things.
UnixJunkie commented
A specialist advises SHA256:
https://crypto.stackexchange.com/questions/957/ripemd-versus-sha-x-what-are-the-main-pros-and-cons
xavierleroy commented
Fixed by #20 .
UnixJunkie commented
Thanks for your responsiveness.
Maybe a new minor release (a git tag) is in order, so that the opam package can be updated.
I know that a fix related to zlib was included recently.