Re: [TLS] Last Call: draft-ietf-tls-rfc4346-bis (The Transport
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Last Call: draft-ietf-tls-rfc4346-bis (The Transport
On Wed, 5 Mar 2008, Martin Rex wrote:
> Rob Dugal wrote:
> >
> > You raise good points but by not having SHA-224 as a supported hash
> > algorithm you effectively prevent anyone from using any certificates which
> > use SHA-224 in TLS 1.2.
> > If the certificate doesn't use a hash algorithm found in the
> > signature_algorithms extension then it cannot be used in TLS 1.2.
>
> Maybe it is a good idea to use this as market pressure to
> keep CAs from doing stupid things, such as issuing X.509
> certificates with SHA-224 instead of SHA-256 in the signature.
>
> (I hope that NIST didn't come up with a braindead suggestion to do so.)
I second this; is it really likely that a CA will issue certs with SHA-224
if SHA-224 is not part of TLS?
--Len.
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.