Google 网上论坛不再支持新的 Usenet 帖子或订阅项。历史内容仍可供查看。

Is Firefox SHA-1 Deprecation Policy configurable?

已查看 534 次
跳至第一个未读帖子

theri...@gmail.com

未读,
2016年9月16日 11:44:122016/9/16
收件人 mozilla-dev-s...@lists.mozilla.org
Working with a client on "workarounds" for avoiding SHA-1 deprecation on a system they are woefully behind on updating for SHA-256 compatible. They asked/stated that Chrome & probably Firefox were "configurable" in regards to shutting out the trust for SHA-1 SSL/TLS certs. I'm skeptical as I haven't seen anything like that.

Is there any configurability in Firefox regarding this (e.g. from a GPO perspective - Windows environment), or is all the SHA-1 deprecation policy embedded in the Firefox code - to be enforced when that update is pushed out (presumably on/around 1/1/17)? Thanks

Rick

s...@gmx.ch

未读,
2016年9月17日 04:50:002016/9/17
收件人 dev-secur...@lists.mozilla.org
I think that's the security.pki.sha1_enforcement_level pref [1][2].

Regards,
Jonas


[1] https://bugzilla.mozilla.org/show_bug.cgi?id=942515#c35
[2]
https://blog.mozilla.org/security/2016/01/06/man-in-the-middle-interfering-with-increased-security/
> _______________________________________________
> dev-security-policy mailing list
> dev-secur...@lists.mozilla.org
> https://lists.mozilla.org/listinfo/dev-security-policy


signature.asc

Andrew R. Whalley

未读,
2016年9月19日 11:28:002016/9/19
收件人 s...@gmx.ch、dev-secur...@lists.mozilla.org
For Chrome, there's the EnableSha1ForLocalAnchors policy that was
introduced in Chrome 54. That will operate as described here
<https://sites.google.com/a/chromium.org/dev/Home/chromium-security/education/tls/sha-1>
.

Andrew
0 个新帖子