Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Chrome only cares about the hash algorithm of the intermediate certificate(s) if the end-entity cert is expiring after 2016. So a SHA-1 certificate expiring in 2015 won't be marked insecure even if it's signed by a SHA-1 intermediate expiring in 2020.

See: http://googleonlinesecurity.blogspot.co.uk/2014/09/gradually...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: