Re: Security Blog about SHA-1

2014-09-26 Thread Erwann Abalea
Le jeudi 25 septembre 2014 22:54:07 UTC+2, Hubert Kario a écrit : - Original Message - From: Chris Palmer p@google.com [...] SHA-1 signature algorithms are not per se bad right now; what's bad is certificate chains using SHA-1 that will/would be valid too far in the future.

Re: Security Blog about SHA-1

2014-09-25 Thread Hubert Kario
- Original Message - From: Chris Palmer pal...@google.com To: Chris Egeland ch...@chrisegeland.com Cc: mozilla-dev-security-pol...@lists.mozilla.org dev-security-policy@lists.mozilla.org Sent: Wednesday, 24 September, 2014 11:53:58 PM Subject: Re: Security Blog about SHA-1 Also

Re: Security Blog about SHA-1

2014-09-24 Thread Rick Andrews
Kathleen, why is mozilla.org still using a SHA-1 cert? ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy