RE: [PHP-DEV] Re: [RFC] Distrust SHA-1 Certificates

From: Date: Wed, 05 Jul 2017 13:29:13 +0000
Subject: RE: [PHP-DEV] Re: [RFC] Distrust SHA-1 Certificates
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.internals 
Request: Send a blank email to internals+get-99763@lists.php.net to get a copy of this message
Hi Davey, > -----Original Message----- > From: me@daveyshafik.com [mailto:me@daveyshafik.com] On Behalf Of Davey > Shafik > Sent: Tuesday, July 4, 2017 8:53 AM > To: Niklas Keller <me@kelunik.com> > Cc: Sara Golemon <pollita@php.net>; Anatol Belski <weltling@outlook.de>; > Jakub Zelenka <bukka@php.net>; PHP Internals <internals@lists.php.net> > Subject: Re: [PHP-DEV] Re: [RFC] Distrust SHA-1 Certificates > > It should be noted that Certificate Authorities (CAs) haven't been issuing SHA-1 > certs since December 31st 2015. > > I think the best solution if possible, would be to treat MD5 and SHA-1 certs as > invalid in _all_ supported versions of PHP and requiring that the verify_peer > option be set to false to accept them. > Wouldn't verify_peer introduce another issue, that not only md5 and sha1 but also any certs would be accepted, that normally shouldn't be? Regards Anatol

« previous php.internals (#99763) next »