OASIS Open Mailing List Archives  ·  All Lists  ·  pkcs11  ·  2013-08

pkcs11 — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Proposal: CKM_SHA512_224, CKM_SHA512_256, CKM_SHA512_T


Hi Bob - Dina wasn't asking about SHA-1, but rather SHA-512/160 - which takes as much space as the SHA-1 digest (good for retrofit into older protocols that didn't leave expansion space). Valerie On 08/ 5/13 12:16 PM, Lockhart, Robert wrote: SHA-1 was deprecated by NIST at the end of 2010 for digital signature generation and is not allowed after December 31, 2013 (specifically in government applications and recommended guidance for the rest of us). It can be used for validation purposes for legacy signatures beyond end of year though but I don't see adding it to the specification if it doesn't already exist in the real world. See Pages 13 & 14 of SP800-131A for more details. http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-131A.pdf Bob L.

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]