Paul:According to the NIST recommendations 2^80 (the strength of SHA-1if none of the attacks prove to be fruitful) is useful for digital signatures until 2010.
The request was about signatures that need to stand for 20 years -- if they are signed today, that is 2027. The NIST recommendations for beyond 2030 seem appropriate, which recommend SHA-256 and a key size of 3072 bits.
Russ At 12:22 PM 1/29/2007, Paul Hoffman wrote:
At 9:38 AM -0500 1/29/07, ROGER YOUNGLOVE wrote:i believe that SHA1 is not sufficent for a 20 year root CA lifespan.It would be useful to know where that belief comes from. To date, there have been no suggestions of any weakness for SHA-1 against preimage attacks. Also to date, no one has suggested that it is possible for anyone to brute-force a cryptographic primitive that would require 2^160 iterations.--Paul Hoffman, Director --VPN Consortium