diff --git a/README.md b/README.md index fd4771f..043f8ef 100644 --- a/README.md +++ b/README.md @@ -38,10 +38,10 @@ sshenc.sh -s ~/.ssh/id_rsa < encrypted.txt ``` ## Notes -[OpenSSL 1.1.1](https://www.openssl.org/docs/man1.1.1/man1/openssl-enc.html) introduced a not backwards compatible change: the default digest to create a key from the passphrase changed from md5 to sha-256. -Also, a new `-iter` parameter to explicitly specify a given number of iterations on the password in deriving the encryption key was added. -Before OpenSSL 1.1.1 this option was not available. -Since the new parameters are more secure, `sshenc.sh` changed to adopt them, so since 2019-11-26, files encrypted with a previous version of `sshenc.sh` will not decrypt. +[OpenSSL 1.1.1](https://www.openssl.org/docs/man1.1.1/man1/openssl-enc.html) introduced a not backwards compatible change: the default digest to create a key from the passphrase changed from md5 to sha-256. +Also, a new `-iter` parameter to explicitly specify a given number of iterations on the password in deriving the encryption key was added. +Before OpenSSL 1.1.1 this option was not available. +Since the new parameters are more secure, `sshenc.sh` changed to adopt them, so since 2019-11-26, files encrypted with a previous version of `sshenc.sh` will not decrypt. To do so, use the prevous `sshenc.sh` script, located at [https://sshenc.sh/sshenc-pre1.1.1.sh](https://sshenc.sh/sshenc-pre1.1.1.sh). ## License