Re: T7338: Make SHA1 non-FIPS and differentiate in the SLI

Werner Koch via Gcrypt-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.libgcrypt.devel
Message-ID <[email protected]>
On Wed, 12 Feb 2025 15:08, Lucas Mulling said:
> On Wed Feb 12, 2025 at 9:50 AM -03, Clemens Lang wrote:

>> If you do a FIPS validation now, you’ll likely get a certificate in
>> ~2 years, which then won’t be valid for 5, but only 3, because the
>> build included support for SHA1.

Makes some sense iff we are not allowed to extend the API.

> Yes, also note that operations with SHA1 are not blocked by default, and
> should work normally unless GCRY_FIPS_FLAG_REJECT_MD_SHA1 is explicitly set.

Alright.  Then let's add this too.


Salam-Shalom,

   Werner


-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

_______________________________________________
Gcrypt-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gcrypt-devel
openpgp-digital-signature.asc (application/pgp-signature, 247 B)
-----BEGIN PGP SIGNATURE-----

iIMEARYKACsWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCZ64g7w0cd2tAZ251cGcu
b3JnAAoJEBnMHJ4IWxB6zUwBAIzB7nJCuP2FP7u32oGaU44La5Qg+3mT6u64ae+a
dDQEAQDsLQq4eG03a+t6kxMBCv/PGdRHCgQ/wOxSRhbVTfJwBg==
=Ym5j
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.