Skip to main content

Compromise of SHA-1 Certificate Thumbprint: A Reality in 2023?

A typical coding pattern is seen in online service APIs that make authentication decisions based on X509 certificate thumbprint comparisons. Typically, the thumbprint provided by the language runtime returns a SHA-1 hash for the certificate, but was not SHA-1 deprecated some years ago because of security concerns?

SANS_Compromise_of_SHA1_Certificate_Thumbprint_A_Reality_in_2023 (PDF, 0.42MB)

14 Feb 2024
ByBarry Markey
Share
All papers are copyrighted

No re-posting of papers is permitted