Re: Security Blog about SHA-1

2014-09-26 Thread Erwann Abalea
Le jeudi 25 septembre 2014 22:54:07 UTC+2, Hubert Kario a écrit :
 - Original Message -
  From: Chris Palmer p@google.com
[...]
  SHA-1 signature algorithms are not per se bad right now; what's bad is
  certificate chains using SHA-1 that will/would be valid too far in the
  future. Between now and 1 Jan 2016, and between then and 1 Jan 2017,
  there is plenty of time to get a new certificate, signed with a
  SHA-256-based signature function.
 
 It's debatable if the 2016 date is good. NIST doesn't agree

According to NIST SP800-57 Part 1, doing a signature with SHA-1 is deprecated 
since 2011 and disallowed since 2014.
We're not too far from NIST.
___
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy


Re: Security Blog about SHA-1

2014-09-25 Thread Hubert Kario
- Original Message -
 From: Chris Palmer pal...@google.com
 To: Chris Egeland ch...@chrisegeland.com
 Cc: mozilla-dev-security-pol...@lists.mozilla.org 
 dev-security-policy@lists.mozilla.org
 Sent: Wednesday, 24 September, 2014 11:53:58 PM
 Subject: Re: Security Blog about SHA-1
 
 Also, there's no problem (from a Chrome UX perspective) because
 Mozilla's certificate expires on 7 December 2015 — well before that
 bad 1 Jan 2017 date, and even before the dodgy 1 Jan 2016 date.
 
 http://googleonlinesecurity.blogspot.com/2014/09/gradually-sunsetting-sha-1.html
 
 SHA-1 signature algorithms are not per se bad right now; what's bad is
 certificate chains using SHA-1 that will/would be valid too far in the
 future. Between now and 1 Jan 2016, and between then and 1 Jan 2017,
 there is plenty of time to get a new certificate, signed with a
 SHA-256-based signature function.

It's debatable if the 2016 date is good. NIST doesn't agree

but yes, as far as Internet certs go, mozilla one is not so bad

-- 
Regards,
Hubert Kario
___
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy


Re: Security Blog about SHA-1

2014-09-24 Thread Rick Andrews
Kathleen, why is mozilla.org still using a SHA-1 cert? 
___
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy