Difference between revisions of "SHA-1 (deprecated)"

From wikieduonline
Jump to navigation Jump to search
Tags: Mobile web edit, Mobile edit
Line 2: Line 2:
  
 
== Status ==  
 
== Status ==  
Disabled in [[OpenSSH 8.8]] September 2021
+
* Disabled in [[OpenSSH 8.8]] September 2021
 +
* Not supported in [[Terraform]] since 1.2 (May 2022)
  
 
== Attacks ==
 
== Attacks ==

Revision as of 06:20, 31 August 2022

wikipedia:SHA-1 is deprecated

Status

Attacks

Certificates are at special risk to the aforementioned SHA1 collision vulnerability as an attacker has effectively unlimited time in which to craft a collision that yields them a valid certificate, far more than the relatively brief LoginGraceTime window that they have to forge a host key signature.

Related

See also

Advertising: