[saag] status of SSL vs SHA-1/MD-5, etc.?
Steven M. Bellovin
smb at cs.columbia.edu
Sun Oct 16 14:24:55 EDT 2005
In message <43527ABA.9040303 at algroup.co.uk>, Ben Laurie writes:
>Steven M. Bellovin wrote:
>> As Eric Rescorla and I showed, though, none of the network protocols
>> are ready for deployment of a new hash function. That is, newer
>> versions of OpenSSL support may SHA-256, but there's no way to
>> negotiate such usage if you don't know the status of the system to
>> which you're talking.
>
>None of the ones you looked at you mean - your survey wasn't comprehensive.
>
No, it wasn't comprehensive, but we looked at the major IETF protocols.
--Steven M. Bellovin, http://www.cs.columbia.edu/~smb
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list