Google Chrome depracating SHA1

gusza

Active Member
Joined
Jun 6, 2011
Messages
34
Reaction score
0
A heads up for admins of secure websites. Google Chrome is upping the requirement for using SHA2 hashing on certificates. Initially from Chrome 39 till Chrome 41 the indicator of security will be changing for websites still using SHA1 hashed certificates. Q1 2015 with the release of Chrome 41 websites still using this will then show as insecure.
This only affects certificates that have an expiry greater than 1 Jan 2017.

Internet Explorer and Firefox will still trust these until 1 Jan 2017. Make sure when you renew you get a SHA2 certificate from your CA.

Further Reading : http://googleonlinesecurity.blogspot.com/2014/09/gradually-sunsetting-sha-1.html
https://konklone.com/post/why-google-is-hurrying-the-web-to-kill-sha-1
https://groups.google.com/a/chromium.org/forum/#!msg/security-dev/2-R4XziFc7A/NDI8cOwMGRQJ
 
Top
Sign up to the MyBroadband newsletter
X