Skip to content

Conversation

@chaodhib
Copy link

Removing SHA-1 as a supported algorithm since it is deprecated according to the specification:

https://tools.ietf.org/html/draft-ietf-httpbis-digest-headers-01

Removing SHA-1 as a supported algorithm since it is deprecated according to the specification
@voltone
Copy link
Owner

voltone commented Feb 28, 2020

Thanks! Dropping SHA-1 from the defaults in the next release is probably a good idea, but I'm going to have to document the algorithms parameter to allow users to re-enable it, for those who need it. After all, the spec you quote is still a draft, and it only says the use of SHA-1 is "NOT RECOMMENDED" (as opposed to MD5 with "MUST NOT be used").

@chaodhib
Copy link
Author

Indeed, that makes sense!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants