Re: MD2

2008-12-30 Thread Florian Weimer
* Ben Bucksch: > Yet, when I went through the cert store, I see not only MD5 certs, but > MD2 certs as well. Partially from VeriSign. How comes? These are self-signatures only. They should not be evaluated. (I hope that NSS doesn't even contain an MD2 implementation. 8-/) __

Re: MD2

2008-12-30 Thread Ian G
On 30/12/08 18:19, Ben Bucksch wrote: On 30.12.2008 17:39, Nelson B Bolyard wrote: The upshot of this is probably going to be that, in a short time, all the world's browsers (and PKI software in general) stop supporting MD5 for use in digital signatures. What is MD2? Is that a weaker predecess