URL: https://github.com/SSSD/sssd/pull/837
Title: #837: p11_child: make OCSP digest configurable

simo5 commented:
"""
@alexey-tikhonov if there is a compatibility issue, I would certainly allow 
sah-1 to be used, but perhaps with an easier way to flip it off in future.

Alsthough it is true @dpward that SHA-1 is allowed, you need to read the fine 
print as well "for applications that do not require collision resistance".

Basically this exclude unique identifier if those are used in any "security" 
sense, while you still can use SHA-1 in applications where a collision is 
handled appropriately (for example hash-maps).

So it really depend more and more on the kinds of usage, which is why it is 
preferable, where possible, to simply move off of SHA-1.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/837#issuecomment-674968818
_______________________________________________
sssd-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to