[cabfpub] SHA-1 changes and certificate lifetimes

Gervase Markham gerv at mozilla.org
Wed Nov 13 09:20:48 MST 2013


On 13/11/13 16:00, Tom Albertson wrote:
> Gerv wrote: [1] Citation needed; but I've seen this quoted in several
> places _______________________________________________
> 
> An appropriate reference for the north of 98% figure for the
> installed base of SHA1 certs would be the academic paper out of the
> University of Michigan, "Analysis of the HTTPS Certificate
> Ecosystem", Table 9 at
> http://conferences.sigcomm.org/imc/2013/papers/imc257-durumericAemb.pdf.
> They performed a very wide scan of certs with findings that correlate
> to our private scans.

That's it, indeed. Thank you.

Gerv


More information about the Public mailing list