unofficial mirror of emacs-devel@gnu.org 
 help / color / mirror / code / Atom feed
* The SHA1 sunset
@ 2016-01-03  9:55 Lars Magne Ingebrigtsen
  2016-01-03 15:37 ` Eli Zaretskii
  2016-01-04 23:04 ` James Cloos
  0 siblings, 2 replies; 12+ messages in thread
From: Lars Magne Ingebrigtsen @ 2016-01-03  9:55 UTC (permalink / raw)
  To: emacs-devel

SHA1 is considered to be likely to be "broken" sometime this year (i.e.,
the NSA will be able to create SHA1 collisions that may enable them to
issue SHA1 certificates to themselves at will for any domain (some
people are very sceptical of this claim)), so I've added warnings about
SHA1 certificates to the "high" `network-security-level' setting in
Emacs 25.1 now.

Other browser makers have announced their intention to refuse to make
any TLS connection using SHA1-signed certificates on January 1st, but
I'm not sure whether they actually went through with this?

We might consider at some point in the future to move this check to the
"medium" (default) setting.

-- 
(domestic pets only, the antidote for overdose, milk.)
   bloggy blog: http://lars.ingebrigtsen.no





^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2016-01-05  7:07 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-01-03  9:55 The SHA1 sunset Lars Magne Ingebrigtsen
2016-01-03 15:37 ` Eli Zaretskii
2016-01-03 19:58   ` John Wiegley
2016-01-04  0:53     ` Lars Magne Ingebrigtsen
2016-01-04  1:05       ` John Wiegley
2016-01-04 22:15         ` Lars Magne Ingebrigtsen
2016-01-04  2:10       ` Mike Gerwitz
2016-01-04 22:14         ` Lars Magne Ingebrigtsen
2016-01-05  6:38           ` Mike Gerwitz
2016-01-05  7:07             ` Lars Magne Ingebrigtsen
2016-01-04 15:42       ` Eli Zaretskii
2016-01-04 23:04 ` James Cloos

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).