Re: Re: [RFC] Distrust SHA-1 Certificates

From: Date: Mon, 29 May 2017 20:17:40 +0000
Subject: Re: Re: [RFC] Distrust SHA-1 Certificates
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-99238@lists.php.net to get a copy of this message
2017-05-29 16:03 GMT+02:00 Lauri Kenttä <lauri.kentta@gmail.com>: > On 2017-05-29 13:58, Niklas Keller wrote: > >> I have updated the RFC to use a "min_signature_bits" setting instead. >> > > At least that name is misleading. Most PHP users would probably wonder why > a setting of 128 does not allow the 160-bit hash from SHA-1 or the 512-bit > RSA. So the name should be more like "min_cryptographic_strength" (possibly > prefixed with "signature_") to make it clear that this is not really about > the bits in signature. > > I'm not totally convinced about this bit approach in general. What happens > if SHA-2 is suddenly broken and people move to SHA-3 of the same length? > I'm open to better suggestions. Regards, Niklas

« previous php.internals (#99238) next »