Structures Membership Contact us IGTF APGridPMA TAGPMA REFEDS SCI WISE Documents Charter Guidelines One Statement Policies CAOPS-WG Wiki Technical Info CA Distribution download Subject Locator Find your local CA About your certificate Newsletter issues Subscribe Service notices Tools download and fetch-crl Technical documentation IGTF OID Registry SHA-2 timeline Meetings CERN, Geneva, CH, Feb 5-7, 2025 Amsterdam, NL, Sept 23-24, 2024 Overview Agendas Intranet and Reviews |
IGTF time line statement on SHA-2 Secure Digest MechanismsHaving consulted the major relying parties, the authority members, and the HASHRAT expert group, and based on the discussions at the APGridPMA, TAGPMA, and EUGridPMA, the following SHA-2 time line has now been endorsed by the IGTF.
If SHA-1 is broken, certificates based on SHA-1 must be revoked within the IGTF RAT determined time line, which may be within one working day. (pending IGTF AHM)
In case of new SHA-1 vulnerabilities, the above schedule may be revised.
Until such a case is demonstrated, there might be exceptional cases where a CA might issue SHA-1 based certs with appropriate warnings and instructions to the subscriber. SHA-224 is not to be used as per the HASHRAT document. Note that SHA-384 does work, though (and in some or many cases is preferred over SHA-512 for compatibility reasons as per https://bugzilla.mozilla.org/show_bug.cgi?id=1129083. Comments to David Groep. This site is hosted at Nikhef, subject to the privacy policy. |