Security/CryptoEngineering/SHA-1: Difference between revisions

Jump to navigation Jump to search
Note completion
(Ref FxCompat)
(Note completion)
 
Line 1: Line 1:
'''NOTE: This work is completed with Firefox 52. Preserved for posterity.'''
Continuing the plan from the [https://blog.mozilla.org/security/2016/10/18/phasing-out-sha-1-on-the-public-web/ Phasing Out SHA-1 On The Public Web blog post]:
Continuing the plan from the [https://blog.mozilla.org/security/2016/10/18/phasing-out-sha-1-on-the-public-web/ Phasing Out SHA-1 On The Public Web blog post]:


Line 58: Line 60:
We can see how often site breakage occurs from TLS Error Reporting statistics, and monitor progress on the rollout via the same telemetry result data format as the prior experiment.
We can see how often site breakage occurs from TLS Error Reporting statistics, and monitor progress on the rollout via the same telemetry result data format as the prior experiment.


=== Planned Sampled Rollout Timeline ===
=== Final Sampled Rollout Timeline ===
(Updated 14 Feb 2017)
(Updated 14 Feb 2017)


Line 96: Line 98:
== Compatibility Help for Site Operators ==
== Compatibility Help for Site Operators ==
The fx-site-compat team has written up the change here: https://www.fxsitecompat.com/en-CA/docs/2016/sha-1-certificates-issued-by-public-ca-will-no-longer-be-accepted/
The fx-site-compat team has written up the change here: https://www.fxsitecompat.com/en-CA/docs/2016/sha-1-certificates-issued-by-public-ca-will-no-longer-be-accepted/
= Completion =
This roll-out completed on schedule, and the total deprecation happened with the release of Firefox 52.
122

edits

Navigation menu