Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecate TLS SHA-1 server signatures #812

Closed
dadrian opened this issue Jun 6, 2023 · 4 comments
Closed

Deprecate TLS SHA-1 server signatures #812

dadrian opened this issue Jun 6, 2023 · 4 comments

Comments

@dadrian
Copy link

dadrian commented Jun 6, 2023

Request for Mozilla Position on an Emerging Web Specification

  • Specification Title: Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2
  • Specification or proposal URL (if available): https://www.rfc-editor.org/rfc/rfc9155.html
  • Explainer URL (if available): n/a
  • Caniuse.com URL (optional): n/a
  • Bugzilla URL (optional):
  • Mozillians who can provide input (optional):

Other information

Chrome Status entry: https://chromestatus.com/feature/4832850040324096

This covers:

  • Removing SHA1 in server signatures
  • Continuing to allow SHA1 in client certificates

Currently:

  • SHA1 is already disallowed in server certificates
  • As far as we know, no browser supports MD5 in any form in TLS.
@zcorpan
Copy link
Member

zcorpan commented Jun 12, 2023

@valenting @dveditz

@martinthomson
Copy link
Member

From the crypto team, we're positive on this. It's pretty hard work to manage the bustage risk, but we've already started work on that.

@zcorpan
Copy link
Member

zcorpan commented Jun 15, 2023

@martinthomson do you think this needs a dashboard entry?

@martinthomson
Copy link
Member

I should have said that this doesn't need an entry. I'll close it now on that basis.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants