[Dcrup] rsa-sha1 usage

James Cloos <cloos@jhcloos.com> Mon, 12 June 2017 21:00 UTC

From: James Cloos <cloos@jhcloos.com>
Date: Mon, 12 Jun 2017 17:00:38 -0400
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/fYkOS9l4SftDNPBegZCt2Pp_rYQ>
Subject: [Dcrup] rsa-sha1 usage
I looked at a corpus of email from this year.  3265010 emails,
including all of spam, good automated and good from humans.

The vast majority of the latter were deliverred via mailing lists.

Just under half (1443757) had a dkim sig.

The ratio of rsa-sha256 to rsa-sha1 was 1244650:198495 which reduces
to about 6.270:1.

So there is a ways to do before sha1 signers disappear.

Nonetheless, I still agree that the update should deprecate sha1.

