Re: [RFC] Distrust SHA-1 Certificates
| From: | Niklas Keller | Date: | Mon, 29 May 2017 20:16:50 +0000 |
| Subject: | Re: [RFC] Distrust SHA-1 Certificates | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-99237@lists.php.net to get a copy of this message | ||
2017-05-29 22:00 GMT+02:00 Jakub Zelenka <bukka@php.net>:
> On Mon, May 29, 2017 at 11:58 AM, Niklas Keller <me@kelunik.com> wrote:
>
>> Morning Internals,
>>
>> I have updated the RFC to use a "min_signature_bits" setting instead.
>>
>>
> Wouldn't be better use security levels instead as it is in OpenSSL? Of
> course I mean just for sig level to not re-implement everything. Basically
> having sig_level or something like that...
>
As we can't use the OpenSSL implementation directly, I don't see any reason
to use arbitrary integers there which you have to look up again. Maybe we
should fine a totally different way.
Regards, Niklas