GNU bug report logs -
#37420
[PATCH] Recommend against SHA-1 for security-related applications
Previous Next
Reported by: Stefan Kangas <stefan <at> marxist.se>
Date: Mon, 16 Sep 2019 08:54:02 UTC
Severity: normal
Tags: patch
Done: Stefan Kangas <stefan <at> marxist.se>
Bug is archived. No further changes may be made.
Full log
View this message in rfc822 format
Lars Ingebrigtsen <larsi <at> gnus.org> writes:
> > +These symbols corresponds to the following hashing algorithms:
> > +
> > + md5 - MD5
> > + sha1 - SHA-1
> > + sha224 - SHA-2 / SHA-224
> > + sha256 - SHA-2 / SHA-384
> > + sha384 - SHA-2 / SHA-384
> > + sha512 - SHA-2 / SHA-512
>
> I'm not sure these really clarify all that much? But I don't object to
> it.
They would help people like me who don't use this stuff very often and
can't remember which one is SHA-1, SHA-2, SHA-3, etc. Of course, one
could expect users to fire up a web browser and search the web for
details instead. But as it stands, we don't document anywhere that
sha512 is indeed SHA-2 as far as I can tell.
> > --- a/test/lisp/emacs-lisp/package-resources/archive-contents
[...]
> Hm... is this related?
No, please disregard that. I fixed it but then attached the wrong
patch to the email.
Best regards,
Stefan Kangas
This bug report was last modified 5 years and 233 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.