Re: T7338: Make SHA1 non-FIPS and differentiate in the SLI
Werner Koch via Gcrypt-devel <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.libgcrypt.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 12 Feb 2025 15:08, Lucas Mulling said: > On Wed Feb 12, 2025 at 9:50 AM -03, Clemens Lang wrote: >> If you do a FIPS validation now, you’ll likely get a certificate in >> ~2 years, which then won’t be valid for 5, but only 3, because the >> build included support for SHA1. Makes some sense iff we are not allowed to extend the API. > Yes, also note that operations with SHA1 are not blocked by default, and > should work normally unless GCRY_FIPS_FLAG_REJECT_MD_SHA1 is explicitly set. Alright. Then let's add this too. Salam-Shalom, Werner -- The pioneers of a warless world are the youth that refuse military service. - A. Einstein _______________________________________________ Gcrypt-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gcrypt-devel
openpgp-digital-signature.asc
(application/pgp-signature, 247 B)
-----BEGIN PGP SIGNATURE----- iIMEARYKACsWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCZ64g7w0cd2tAZ251cGcu b3JnAAoJEBnMHJ4IWxB6zUwBAIzB7nJCuP2FP7u32oGaU44La5Qg+3mT6u64ae+a dDQEAQDsLQq4eG03a+t6kxMBCv/PGdRHCgQ/wOxSRhbVTfJwBg== =Ym5j -----END PGP SIGNATURE-----