Hacker News new | past | comments | ask | show | jobs | submit login

Anybody know what the easiest way to determine if your certificate is affected? I looked at my certificate and it says Signature Algorithm is "SHA-1 with RSA Encryption". Is this affected? When I viewed the certificate for google.com it also said "SHA-1 with RSA Encryption".



Yes. Both those certificates are affected. If I had to guess, Google will begin issuing a non-SHA1 cert to modern browser users and a SHA1 certificate to older browsers before the end of September. I wish I could give you easy advice on how to do that yourself.


Thanks for the reply, I thought I was understanding it correctly. Now that I think about it more, they will still be able to use SHA-1 and not be affected because they will surely just issue another certificate that only lasts 1 year which means it will expire before January 2016, so it will still show up as Green in Chrome. Sucks for me because we paid for a cert through July 2017 and now we'll probably have to pay more money to get a non-SHA1 cert.


your CA should offer you free re-issuing any time you want to regenerate it


How? I would expect anything that might identify the browser would be sent after the encryption was set up?


The list of supported cyphersuites is sent before the encryption is set up.

Though some browsers lie in that list and list things they don't actually support, of course...




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: