2 ms·
The company I work for is in the process of migrating off of SHA-1 certs, and the amount of due diligince that has to go into this sort of an upgrade is incredi
by mdlowman 11y ago
The company I work for is in the process of migrating off of SHA-1 certs, and the amount of due diligince that has to go into this sort of an upgrade is incredible.
It involves analyzing full logs of all supported client enctypes and tracking down the full set of "flavors" of clients that only do SHA-1.
At the end of the day, you're going to break people, and it's all about minimizing how many people that is. Imagine the situation with hardware devices in the field from ten or so years ago. You can't update them and their software rev only supports SHA-1. What do you do?
(You break them.)