{"id":3132,"date":"2016-10-24T15:19:16","date_gmt":"2016-10-24T15:19:16","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3132"},"modified":"2018-09-26T07:49:38","modified_gmt":"2018-09-26T11:49:38","slug":"firefox-will-display-sha-1-error","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/firefox-will-display-sha-1-error\/","title":{"rendered":"Firefox Will Display Error For SHA-1 Certificates in 2017"},"content":{"rendered":"<h2>Firefox will display a full page interstitial to warn users about SHA-1.<\/h2>\n<p>At this point, the elimination of SHA-1 should not be a surprise to anyone. The hashing algorithm, which was widely used to prove the authenticity of SSL certificates until last year, is very close to being entirely replaced. <a href=\"https:\/\/blog.mozilla.org\/security\/2016\/10\/18\/phasing-out-sha-1-on-the-public-web\/\">Mozilla&#8217;s Firefox browser is ready to take the next step in that process<\/a>.<\/p>\n<p>In 2017, Firefox will start showing an <a href=\"https:\/\/support.mozilla.org\/en-US\/kb\/connection-untrusted-error-message\">\u201cUntrusted Connection\u201d error<\/a> when a SHA-1 certificate is encountered. This error will be overridable and be a full page interstitial.<\/p>\n<p>J.C. Jones, who is the head of cryptography engineering at Mozilla, said \u201can algorithm we\u2019ve depended on for most of the life of the Internet \u2014 SHA-1 \u2014 is aging, due to both mathematical and technological advances.\u201d<\/p>\n<p>They will be testing this deprecation starting next month for a \u201csubset of [Firefox] Beta users,\u201d in order to ensure that everything goes smoothly. When Firefox 51 releases in early 2017, they will roll out the new warning in a similar way.<\/p>\n<p>The policy will not apply to manually-imported roots to accommodate enterprise use.<\/p>\n<p>The majority of sites have successfully transitioned to SHA-2. SSL Pulse, which records monthly data on 200,000 of the largest SSL-enabled sites, reports that only 3.4% of sites are using SHA-1 certificates. This is a significant fall from the beginning of 2016, when 13.2% of sites were using SHA-1.<\/p>\n<p>Mozilla estimates that actual use of SHA-1 is even lower. Their <a href=\"https:\/\/telemetry.mozilla.org\/new-pipeline\/evo.html#!aggregates=bucket-1!bucket-2!bucket-3!bucket-4!bucket-5&amp;cumulative=0&amp;end_date=null&amp;keys=&amp;max_channel_version=release%252F48&amp;measure=CERT_CHAIN_SHA1_POLICY_STATUS&amp;min_channel_version=release%252F46&amp;product=Firefox&amp;sanitize=1&amp;sort_keys=submissions&amp;start_da\">Firefox Telemetry data<\/a> shows that less than 1% of TLS sessions are using SHA-1 certificates. This measurement can give us a better idea of how significant SHA-1 use is than just looking at the number of sites using SHA-1 certs, since some of those can have extremely low traffic.<\/p>\n<p>SHA-1 certificates will naturally die out as regulations from the CA\/Browser Forum have largely banned the issuance of new SHA-1 certificates since January 1st of this year. As existing SHA-1 certificates expire, they will be replaced with SHA-2 certificates.If you have any sites still using SHA-1 certificates, it is time to upgrade.<\/p>\n<p>If you have any sites still using SHA-1 certificates, it is time to upgrade.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Firefox will display a full page interstitial to warn users about SHA-1. At this point, the elimination of SHA-1 should not be a surprise to anyone. The hashing algorithm, which&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3134,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[151,192,156,136,161],"class_list":["post-3132","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-firefox","tag-mozilla","tag-sha-1","tag-ssl","tag-tls","post-with-tags"],"views":10109,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/10\/Depositphotos_125363292_m-2015-1.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3132"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3132\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3134"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}