[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: SHA 1 vs. SHA 256 for Root CA




At 4:02 PM -0500 1/29/07, Russ Housley wrote:
Roger & Steve:

Also, upon further reflection, I agree that since this is a self-signed cert, which presumably has been delivered via an out-of-band path that is considered integrity secure, the concerns over use of SHA-1 may be overstated.

I think that Santosh's note explained the point about self-signed certificates. In my response, I assumed that the same signature algorithm would be used for certificates that are subordinate to the self-signed certificate. Thus my comments about 20 year validity periods.

If the self-signed public keys are being used to validate digital signatures, similar issues arise.

Russ

Agreed.

Roger, where do you pan to use the hash algorithm in question?

Steve