Difference between revisions of "SHA-1 (deprecated)"

From wikieduonline
Jump to navigation Jump to search
Line 1: Line 1:
[[wikipedia:SHA-1]]
+
[[wikipedia:SHA-1]] is deprecated
  
 +
== Status ==
 
Disabled in [[OpenSSH 8.8]] September 2021
 
Disabled in [[OpenSSH 8.8]] September 2021
  

Revision as of 10:22, 26 October 2021

wikipedia:SHA-1 is deprecated

Status

Disabled in OpenSSH 8.8 September 2021

Attacks

Certificates are at special risk to the aforementioned SHA1 collision vulnerability as an attacker has effectively unlimited time in which to craft a collision that yields them a valid certificate, far more than the relatively brief LoginGraceTime window that they have to forge a host key signature.

See also

Advertising: