Firefox Will Display Error For SHA-1 Certificates in 2017
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...

Firefox Will Display Error For SHA-1 Certificates in 2017

Firefox will display a full page interstitial to warn users about SHA-1.

At this point, the elimination of SHA-1 should not be a surprise to anyone. The hashing algorithm, which was widely used to prove the authenticity of SSL certificates until last year, is very close to being entirely replaced. Mozilla’s Firefox browser is ready to take the next step in that process.

In 2017, Firefox will start showing an “Untrusted Connection” error when a SHA-1 certificate is encountered. This error will be overridable and be a full page interstitial.

J.C. Jones, who is the head of cryptography engineering at Mozilla, said “an algorithm we’ve depended on for most of the life of the Internet — SHA-1 — is aging, due to both mathematical and technological advances.”

They will be testing this deprecation starting next month for a “subset of [Firefox] Beta users,” in order to ensure that everything goes smoothly. When Firefox 51 releases in early 2017, they will roll out the new warning in a similar way.

The policy will not apply to manually-imported roots to accommodate enterprise use.

The majority of sites have successfully transitioned to SHA-2. SSL Pulse, which records monthly data on 200,000 of the largest SSL-enabled sites, reports that only 3.4% of sites are using SHA-1 certificates. This is a significant fall from the beginning of 2016, when 13.2% of sites were using SHA-1.

Mozilla estimates that actual use of SHA-1 is even lower. Their Firefox Telemetry data shows that less than 1% of TLS sessions are using SHA-1 certificates. This measurement can give us a better idea of how significant SHA-1 use is than just looking at the number of sites using SHA-1 certs, since some of those can have extremely low traffic.

SHA-1 certificates will naturally die out as regulations from the CA/Browser Forum have largely banned the issuance of new SHA-1 certificates since January 1st of this year. As existing SHA-1 certificates expire, they will be replaced with SHA-2 certificates.If you have any sites still using SHA-1 certificates, it is time to upgrade.

If you have any sites still using SHA-1 certificates, it is time to upgrade.