Do you remember where you read that? As far as I can see FIPS 140-3 is still in draft and sha-1 is still in the list. But considering the draft has been around for years it would be good to have a heads up if it get's deprecated when the final release comes around.

On 8/7/2012 12:15 PM, Wei Zhang wrote:
We have requirement to use FIPS 140-2 hashing algorithm. I read somewhere that md5sum or sha1sum will not be on the approve list in the future. assuming that is true, i would have to remove OSSEC off 25+ servers. dont really want to do that.

On Tue, Aug 7, 2012 at 12:43 PM, dan (ddp) <ddp...@gmail.com <mailto:ddp...@gmail.com>> wrote:

    On Tue, Aug 7, 2012 at 12:26 PM, Wei Zhang <acur...@gmail.com
    <mailto:acur...@gmail.com>> wrote:
    > Is there a place for feature request? +1 for SHA-256 or SHA512
    >

    https://bitbucket.org/dcid/ossec-hids In the issues section

    Is there a specific reason you want one of these? Are these required
    by something specific?

    >
    > On Tue, Aug 7, 2012 at 12:13 PM, dan (ddp) <ddp...@gmail.com
    <mailto:ddp...@gmail.com>> wrote:
    >>
    >> On Tue, Aug 7, 2012 at 12:10 PM, Diezou <secur...@diezou.net
    <mailto:secur...@diezou.net>> wrote:
    >> > Hello,
    >> > Can OSSEC 2.6 support SHA-256 or SHA-512 algorithms?
    >> > If not (that I think after docs reading), I'd like to know if
    these
    >> > algorithms act as a part of future roadmap?
    >> > Thanks
    >>
    >> No, and not really.
    >
    >



Reply via email to