Re: Can we deprecate NSS signtool?

2017-07-03 Thread Kyle Hamilton
http://docs.oracle.com/javase/7/docs/technotes/tools/windows/jarsigner.html It is probably not as complicated to change the default in a compatible way as you think. However, I don't know if anyone still uses signtool. -Kyle H On Mon, Jul 3, 2017 at 4:49 AM, Kai Engert wrote: > The NSS util

Can we deprecate NSS signtool?

2017-07-03 Thread Kai Engert
The NSS utility "signtool" is hardcoded to use SHA1 when creating a digital signature. As I've described in this bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1345528 it might be complicated to change the default to a more secure hash algorithm in a compatible way. I wonder who still depend