2 ms·
Why can't you just verify that the whole chain is SHA-1 instead of using the expiration date as a heuristic?
by v13inc 12y ago
Why can't you just verify that the whole chain is SHA-1 instead of using the expiration date as a heuristic?
- Dylan16807 12y agoBecause then everything will seem fine until 2017 at which point all the sites break at once. Using the expiration date makes it gradual and shows problems when certificate updates are tested.