My favorites | Sign in
Logo
                
New issue | Search
for
| Advanced search | Search tips
Issue 124: Provide mechanism to only allow HMAC_SHA256 associations
  Back to list
Status:  Fixed
Owner:  andrewarnott
Closed:  Aug 2008
Type-Enhancement
Priority-Medium
Release-2.4


Sign in to add a comment
 
Reported by andrewarnott, Aug 11, 2008
HMAC_SHA1 is broken because the SHA-1 hash has been broken (deliberate
collisions can now be generated).  For high security RP sites, a switch to
allow only SHA256 associations should be available.
Comment 1 by andrewarnott, Aug 13, 2008
Fixed in master.
Status: Fixed
Comment 2 by andrewarnott, Aug 19, 2008
(No comment was entered for this change.)
Labels: -release-3.0 Release-2.4
Sign in to add a comment

Hosted by Google Code