Re: [keyassure] crypto hash alg deprecation is a myth

Rob Stradling <rob.stradling@comodo.com> Thu, 03 March 2011 07:45 UTC

Return-Path: <rob.stradling@comodo.com>
X-Original-To: keyassure@core3.amsl.com
Delivered-To: keyassure@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3A3A83A6942 for <keyassure@core3.amsl.com>; Wed, 2 Mar 2011 23:45:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.677
X-Spam-Level:
X-Spam-Status: No, score=-5.677 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_MISMATCH_NET=0.611, HOST_MISMATCH_COM=0.311, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xhY9I71t3oHJ for <keyassure@core3.amsl.com>; Wed, 2 Mar 2011 23:45:45 -0800 (PST)
Received: from ian.brad.office.comodo.net (brad.comodogroup.com [82.109.38.202]) by core3.amsl.com (Postfix) with ESMTP id C677F3A6403 for <keyassure@ietf.org>; Wed, 2 Mar 2011 23:45:41 -0800 (PST)
Received: (qmail 30840 invoked by uid 1000); 3 Mar 2011 07:46:46 -0000
Received: from nigel.brad.office.comodo.net (HELO nigel.localnet) (192.168.0.58) by ian.brad.office.comodo.net (qpsmtpd/0.40) with (AES256-SHA encrypted) ESMTPS; Thu, 03 Mar 2011 07:46:46 +0000
From: Rob Stradling <rob.stradling@comodo.com>
To: keyassure@ietf.org, mrex@sap.com
Date: Thu, 03 Mar 2011 07:46:52 +0000
User-Agent: KMail/1.13.5 (Linux/2.6.32-gentoo-r7; KDE/4.4.5; i686; ; )
References: <201103030509.p2359FSK025866@fs4113.wdf.sap.corp>
In-Reply-To: <201103030509.p2359FSK025866@fs4113.wdf.sap.corp>
MIME-Version: 1.0
Content-Type: Text/Plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-Id: <201103030746.53024.rob.stradling@comodo.com>
Cc: Phillip Hallam-Baker <hallam@gmail.com>
Subject: Re: [keyassure] crypto hash alg deprecation is a myth
X-BeenThere: keyassure@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Key Assurance With DNSSEC <keyassure.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/keyassure>, <mailto:keyassure-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyassure>
List-Post: <mailto:keyassure@ietf.org>
List-Help: <mailto:keyassure-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyassure>, <mailto:keyassure-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Mar 2011 07:45:46 -0000

On Thursday 03 Mar 2011 05:09:15 Martin Rex wrote:
> Phillip Hallam-Baker wrote:
> > Further, even though we stopped using MD5 in the mid 90s
> 
<snip>
> Firefox happily verifies md5WithRsaEncryption signatures on TLS server
> certs.

Not for much longer.

https://wiki.mozilla.org/CA:MD5and1024 says:
"    * June 30, 2011 – Mozilla will stop accepting MD5 as a hash algorithm for 
intermediate and end-entity certificates. After this date software published 
by Mozilla will return an error when a certificate with an MD5-based signature 
is used.
          o This change is being tracked in 
https://bugzilla.mozilla.org/show_bug.cgi?id=590364"

<snip>
> MSIE 8 on Windows 7 (and prior) will happily talk to TLS servers
> using certs signed not only with md5WithRsaSignature, but also
> md2WithRsaSignature and even (**cough**) md4WithRsaSignature!

http://technet.microsoft.com/en-us/library/cc751157.aspx#EMAA says:
"In the event of an imminent MD5 pre-image attack
Microsoft may update Windows to reject all MD2, MD4 or MD5 end-entity and 
subordinate CA certificates when it has reasons to believe that successful MD5 
pre-image attacks are imminent."

Perhaps somebody should ask them to consider switching off MD2 and MD4 sooner 
than that.

<snip>
> (If it is possible to disable md5WithRsaEncryption signature verification
>  in Firefox 3.5 -- then it is sufficiently well hidden that I don't
>  see it.)

https://bugzilla.mozilla.org/show_bug.cgi?id=590364 suggests setting the 
following environment variable:

NSS_HASH_ALG_SUPPORT=-MD2,-MD5

<snip>

Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online