Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Security Infrastructure

Akamai to Kill Support for SHA-1 Certificates

Akamai on Wednesday announced that as of Dec 27, 2016 it will no longer support SHA-1 certificates, after only handing out SHA-256 certificates for a period of time starting Nov. 3.

Akamai on Wednesday announced that as of Dec 27, 2016 it will no longer support SHA-1 certificates, after only handing out SHA-256 certificates for a period of time starting Nov. 3.

Last year, a team of security researchers demonstrated that the cost of breaking the SHA1 cryptographic hash function is much lower than previously believed, and tech companies decided to act upon that fast. As a result, Google, Mozilla and Microsoft announced plans to retire SHA-1 in their browsers. Firefox will soon display an error message when encountering SHA-1 certificates.

As of Jan. 1, 2016, most Certificate Authorities no longer issue SHA-1 certificates and the move away from the insecure standard is expected to be completed by Jan. 1, 2017. And with Chrome, Firefox, Internet Explorer and Edge also killing support for the hash function, the only obvious step is to follow suit, Erik Nygren, Fellow and Chief Architect in the Akamai Platform, notes.

Akamai switched to RSA SHA-256 certificates in early 2015 and now says that over 95% of the customer certificates served on Akamai’s Secure CDN have moved to RSA SHA-256. Even so, custom clients or applications that break when the SHA-1 certificate rotates into a SHA-256 certificate continue to emerge, and available options are limited, Nygren says.

One issue that could emerge from the sunset of SHA-1 in browsers is user’s inability to access their preferred websites, provided that these didn’t transition away from SSL certificates using the SHA-1 cryptographic hash function. Thus, companies such as Facebook, CloudFlare, and even Twitter called for a delay in moving away from SHA-1 certificates. 

Akamai too has been “trying to stretch out SHA-1 support as far as safely possible,” Nygren notes, especially since the company still sees a significant number of handshakes completing and using SHA-1. Handing out SHA-1 will cease being possible at the end of 2016, because it would involve serving an expired or invalid certificate to clients (although they might not support SHA-256, they are likely to display an error when encountering an expired certificate).

“To avoid making the change to our shared certificate on New Year’s Eve, we will be shutting off the SHA-1 certificate, and will always hand out an RSA SHA-256 or ECDSA SHA-256 certificate, on or around December 27. Additionally, on November 3, we will be only handing out SHA-256 certificates for a period of time. The goal is to help customers identify a dependance on SHA-1 and give them time to make changes ahead of end-of-year freezes,” Nygren says.

Some companies might have a local CA root signing certificate for internal sites, but they too are advised to make sure that SHA-1 certs are no longer in use. While some browsers might have exceptions for these locally installed CA roots, others don’t. Chrome, for example, will return a fatal network error even in these cases.

Advertisement. Scroll to continue reading.

At this point, the industry is determined to sunset SHA-1 at the end of 2016/beginning of 2017, yet SHA-1 root certificates that perform signatures with SHA-256 will continue to work. “This is because the risk exposure is around performing signatures over a hash function where two certificate inputs can be readily found that hash to the same value,” Nygren explains.

He also notes that all site admins should make sure that they have rotated over to using SHA-256 certificates before the end of the year draws nearer. Applications or devices relying on Akamai’s shared certificate should be tested for handling SHA-256 certificates, so that no disruption appears when Akamai drops SHA-1 support.

Related: New Collision Attack Lowers Cost of Breaking SHA1

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Management & Strategy

Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.

Security Infrastructure

Security vendor consolidation is picking up steam with good reason. Everyone wants to improve security efficiency and effectiveness while paying for less.

Cloud Security

The term ‘zero trust’ is now used so much and so widely that it has almost lost its meaning.

Funding/M&A

Responding to Cyber Threats Against Critical Infrastructures: Wired Business Media Acquires Long Running ICS Cybersecurity Conference Series

Security Infrastructure

Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a...

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Security Infrastructure

Comcast jumps into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace.