badssl.com icon indicating copy to clipboard operation
badssl.com copied to clipboard

Add MD5 and SHA-1 server signatures

Open davidben opened this issue 3 years ago • 2 comments

These correspond to the configurations deprecated by RFC 9155. I've marked MD5 as "bad" because it really should have been out of clients by now. I've marked SHA-1 as "dubious" for now because it's analogous to TLS 1.0/1.1, and clients still support it for now (but hopefully not for much longer).

(I just copied the existing configuration for the cipher suite pages. Not positive if I've done it right.)

davidben avatar Oct 19 '22 19:10 davidben

@christhompson

davidben avatar Oct 19 '22 19:10 davidben

So landing this will be blocked on me completing the server upgrade after all.

Oof. In the likely event the upgrade makes it impossible to sign MD5, that's no big deal. I don't think any browser supports that anyway. I just added it for completeness.

Clearly we should fork the Go TLS stack and write a custom TLS terminator to sit in front of NGINX... :-)

davidben avatar Oct 24 '22 22:10 davidben