[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SHA 1 vs. SHA 256 for Root CA




Paul:

According to the NIST recommendations 2^80 (the strength of SHA-1if none of the attacks prove to be fruitful) is useful for digital signatures until 2010.

The request was about signatures that need to stand for 20 years -- if they are signed today, that is 2027. The NIST recommendations for beyond 2030 seem appropriate, which recommend SHA-256 and a key size of 3072 bits.

Russ

At 12:22 PM 1/29/2007, Paul Hoffman wrote:

At 9:38 AM -0500 1/29/07, ROGER YOUNGLOVE wrote:
i believe that SHA1 is not sufficent for a 20 year root CA lifespan.

It would be useful to know where that belief comes from. To date, there have been no suggestions of any weakness for SHA-1 against preimage attacks. Also to date, no one has suggested that it is possible for anyone to brute-force a cryptographic primitive that would require 2^160 iterations.

--Paul Hoffman, Director
--VPN Consortium