You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@qpid.apache.org by "Rob Godfrey (JIRA)" <ji...@apache.org> on 2015/12/01 16:43:11 UTC

[jira] [Resolved] (QPID-6923) Make AutoGeneratedSelfSigned default to SHA256WithRSA rather than SHA1WithRSA to help users comply with SHA-1 sunset

     [ https://issues.apache.org/jira/browse/QPID-6923?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Rob Godfrey resolved QPID-6923.
-------------------------------
       Resolution: Fixed
    Fix Version/s: qpid-java-6.1

Change looks good to me - we should put this into 6.0

> Make AutoGeneratedSelfSigned default to SHA256WithRSA rather than SHA1WithRSA to help users comply with SHA-1 sunset
> --------------------------------------------------------------------------------------------------------------------
>
>                 Key: QPID-6923
>                 URL: https://issues.apache.org/jira/browse/QPID-6923
>             Project: Qpid
>          Issue Type: Bug
>          Components: Java Broker
>            Reporter: Keith Wall
>            Assignee: Rob Godfrey
>             Fix For: qpid-java-6.1
>
>
> QPID-6604 introduced support for auto generated self-signed certificates but it defaults the signature algorithm to {{SHA1withRSA}}.  With the impending SHA1 sunset, it is better this default is be {{SHA256withRSA}}.
> JDK 7 is required to support  SHA256withRSA [1]
> [1] https://docs.oracle.com/javase/7/docs/api/java/security/Signature.html



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org