2 ms·
In the case of SSL certificates, the SHA-1 or SHA-256 hash algorithm is being used to verify the integrity of the certificate. It assures that the information i
by Gregordinary 11y ago
In the case of SSL certificates, the SHA-1 or SHA-256 hash algorithm is being used to verify the integrity of the certificate. It assures that the information in the "To be signed" certificate sequence (e.g. domain name, organization, country, etc.) matches what the CA signed.
While the motivation to move to SHA-256 is motivated by SHA-1's susceptibility to collisions, the concern for many is that legacy systems may not support SHA-256, meaning older clients won't be able to connect to sites using SHA-256 signed certificates. In general as long as a client is on Windows XP SP3+ or OS X 10.5+ they'll be all set [1].
While this isn't a feature of X.509 certs, if you were to implement "Dual Hashes" (using SHA1/SHA2 as an example), you'd have a scenario where older operating systems may not be able to validate the newer hash and only the older, now insecure hash essentially defeating the purpose.
Changing a cert from SHA-1 to SHA-256 in most cases is a matter of reissuing or re-keying your certificate with your CA. Most CAs offer this for free, though some may charge.
--
Side note: In the case of document signatures, there is an XML signature standard called XAdES. There are different levels of XAdES signatures, the strongest being XAdES-A [2] where the -A is for "Archive". When you place a signature on a document, to make it valid long term (beyond the expiration date of your certificate) you can add a 3rd party timestamp and embed revocation data into the signature. But what happens when the hash algorithm used by the timestamp server is considered insecure? XAdES allows you to go back and add additional timestamps with newer hash algorithms to make this "future proof". Similar, but not quite the same as what you were suggesting.
--
[1] SHA-256 Compatibility: https://support.globalsign.com/customer/en/portal/articles/1499561-sha-256-compatibility https://support.globalsign.com/customer/en/portal/articles/1...
[2] XAdES-A: http://www.w3.org/TR/XAdES/#Syntax_for_XAdES-A_form http://www.w3.org/TR/XAdES/#Syntax_for_XAdES-A_form