Re: SHA256/GCM DHE support when SHA1 support is dropped

2015-11-09 Thread Kurt Roeckx
On 2015-11-06 17:47, loths...@gmail.com wrote: https://bugzilla.mozilla.org/s... [mozilla.org] Firefox only currently supports DHE with SHA1. Are they going add support for SHA256 DHE when they disable SHA1? The dropping of SHA1 is only in certificates, not in any of the cipher suites.

SHA256/GCM DHE support when SHA1 support is dropped

2015-11-06 Thread lothsahn
https://bugzilla.mozilla.org/s... [mozilla.org] Firefox only currently supports DHE with SHA1. Are they going add support for SHA256 DHE when they disable SHA1? To quote Michael Staruch from the above link: It looked more like attempts to discredit DHE and push everyone into ECC. And I am not

RE: SHA256/GCM DHE support when SHA1 support is dropped

2015-11-06 Thread Yuhong Bao
Mozilla is not dropping HMAC-SHA1 TLS ciphersuites. TLS 1.0 would not work without them. > Date: Fri, 6 Nov 2015 08:47:45 -0800 > Subject: SHA256/GCM DHE support when SHA1 support is dropped > From: loths...@gmail.com > To: mozilla-dev-

Re: SHA256/GCM DHE support when SHA1 support is dropped

2015-11-06 Thread Gijs Kruitbosch
On 06/11/2015 16:47, loths...@gmail.com wrote: https://bugzilla.mozilla.org/s... [mozilla.org] For clarity, the scrubbed link here was: https://bugzilla.mozilla.org/show_bug.cgi?id=1084554 ~ Gijs ___ dev-security-policy mailing list