{"id":681,"date":"2014-10-08T10:36:44","date_gmt":"2014-10-08T10:36:44","guid":{"rendered":"https:\/\/www.rapidsslonline.com\/blog\/?p=681"},"modified":"2022-04-22T01:09:48","modified_gmt":"2022-04-22T06:39:48","slug":"google-exclude-sha-1-upcoming-chrome-browsers","status":"publish","type":"post","link":"https:\/\/www.rapidsslonline.com\/blog\/google-exclude-sha-1-upcoming-chrome-browsers\/","title":{"rendered":"Google to Exclude SHA-1 in the Upcoming Chrome Browsers"},"content":{"rendered":"<h2>Understand SHA-1 Algorithm Weakness As Per Google Standards<\/h2>\n<p>The software giant Google\u00a9 has made a crucial decision about <a title=\"deprecating SHA-1 signature algorithm\" href=\"https:\/\/blog.chromium.org\/2014\/09\/gradually-sunsetting-sha-1.html\" target=\"_blank\" rel=\"noopener\"><strong>deprecating SHA-1 signature algorithm<\/strong><\/a> in their extremely popular Chrome browser in order to strengthen the security of the Internet.<\/p>\n<p>Google\u00a9 has always taken strong actions when it comes to users&#8217; data protection on the Internet. This time, for the sake of Internet security, they have planned to <a title=\"stop trusting the SHA-1 algorithm\" href=\"https:\/\/www.zdnet.com\/article\/google-accelerates-end-of-sha-1-support-certificate-authorities-nervous\/\" target=\"_blank\" rel=\"noopener\"><strong>stop trusting the SHA-1 algorithm<\/strong><\/a>, which might be susceptible to several cyber-attacks due to inability to keep up with the latest techniques used by the hackers. Google\u00a9 has been putting in the best efforts to build secure measures for its users.<\/p>\n<p>So it looks like it is finally about time to say good bye to the SHA-1 signature algorithm due to this major modification from Google. So, let\u2019s take a quick look at these changes and how the users need to manage website security based on these developments.<\/p>\n<ul>\n<li><strong>What is SHA-1 signature algorithm?<\/strong>\n<p>SHA stands for \u201cSecure Hash Algorithm\u201d and the version SHA-1 works on the single hash function, which is known to be <a title=\"vulnerable\" href=\"https:\/\/www.schneier.com\/blog\/archives\/2012\/10\/when_will_we_se.html\" target=\"_blank\" rel=\"noopener\"><strong>vulnerable<\/strong><\/a> according to many web security experts.<\/li>\n<li><strong>What is SHA-2 signature algorithm?<\/strong>\n<p>SHA-2 is the latest version in SHA Algorithm history, and it is the next generation SHA-2 signature algorithm, which includes multiple hash functions to protect user\u2019s data while exchanging them on the Internet.<\/li>\n<li><strong>Is it safe to use SHA-1?<\/strong>\n<p>The vulnerabilities of SHA-1 are very well known and have been demonstrated many times over. In a practical live environment, it is still safe to use the SHA-1 signature algorithm. However, as per <a title=\"critics from SSL experts\" href=\"https:\/\/support.google.com\/chrome\/answer\/95617?hl=en\" target=\"_blank\" rel=\"noopener\"><strong>critics and SSL experts<\/strong><\/a>, SHA-1 will create security vulnerabilities in near future on the Internet. For that reason, best practices do not recommend SHA-1.<\/li>\n<li><strong>What if my existing SSL certificate is SHA-1?<\/strong>\n<p>If your certificate is based on SHA-1 algorithm, it is very easy to get it exchanged for a SHA-2 certificate. All you need to do is re-issue your SSL certificate by choosing the algorithm as SHA-2.<\/li>\n<li><strong>Which Certificate Authorities (CAs) have this new SHA-2 algorithm?<\/strong>\n<p>There are plenty of SSL certificate vendors on the Internet but it gets very difficult to find out exactly which CA has migrated all its SSL certificates and Code Signing Certificates to SHA-2 signature algorithm. We have carried out a little research on this and found that Symantec&#x2122;, GeoTrust\u00ae, Thawte&#x2122;, and RapidSSL&#x2122; offer <a href=\"https:\/\/www.rapidsslonline.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Low Price SSL certificates<\/strong><\/a> with SHA-2 algorithm and technical support by the team of experts.<\/li>\n<li><strong>What is the difference between SHA-1 and SHA-2 algorithm?<\/strong>\n<p>\t<a title=\"SHA-1 signature algorithm\" href=\"https:\/\/en.wikipedia.org\/wiki\/SHA-1\" target=\"_blank\" rel=\"noopener\"><strong>SHA-1 signature algorithm<\/strong><\/a> works on a single 128-bit hash function, whereas SHA-2 signature algorithm works on multiple hash functions.<br \/>\n\t<a title=\"SHA-2 signature algorithm\" href=\"https:\/\/en.wikipedia.org\/wiki\/SHA-2\" target=\"_blank\" rel=\"noopener\"><strong>SHA-2 signature algorithm<\/strong><\/a> is stronger than SHA-1 because it has multiple hash function such as SHA-224, SHA-256, SHA-384, SHA-512, SHA-512\/224, SHA-512\/256 and out of them SHA-256 bit is widely established and more demanded hash function algorithm. The suffix numbers indicate bit length. So SHA-2\u2019s full set of functions are higher bit-length than SHA-1 and therefore are more secure.<\/li>\n<li><strong>What is Google&#8217;s preparation for the elimination of SHA-1?<\/strong>\n<p>Here is how the upcoming versions of the Google Chrome browser shall react to a SHA-1 SSL certificate.<\/li>\n<\/ul>\n<ul>\n<li><strong>Chrome 39<\/strong> \u2013 Public release in early November 2014\n<p>Websites secured by SHA-1 certificates that expire in 2017 or later, on this version will be treated as &#8216;Secure, but with minor errors&#8217;. A small yellow triangle on the padlock will be displayed on the URL as shown below:<\/p>\n<p><a href=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-682\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39.png\" alt=\"chrome version 39 error\" width=\"216\" height=\"74\" \/><\/a><\/li>\n<li><strong>Chrome 40<\/strong> \u2013 Branch Point \u2013 November 7 2014 &amp; Stable after Holiday Season\n<p>Websites with SHA-1 SSL certificates expiring between June 1 2016 to December 31 2016 will trigger the &#8216;Secure, but with minor errors&#8217; warning as mentioned above.<\/p>\n<p>And the websites secured with SHA-1 SSL certificates expiring on or after January 1 2017, will be treated as &#8216;neutral, lacking security&#8217;. In this, the padlock will be replaced by a blank page icon, as shown in the image below:<\/p>\n<p><a href=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-40.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-683\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-40.png\" alt=\"chrome version 40\" width=\"248\" height=\"77\" \/><\/a><\/li>\n<li><strong>Chrome 41<\/strong> \u2013 Branch Point \u2013 Q1 2015\n<p>All the websites relying on SHA-1 SSL certificates expiring between January 1 2016 to December 31 2016 will trigger the &#8216;Secure, but with minor errors&#8217;, as described above.<\/p>\n<p>And all SHA-1 SSL certificates expiring on or after January 1 2017 will be treated as &#8216;affirmatively insecure&#8217;. In this, a red cross and red strike-through is displayed on the URL, as shown in the image below:<\/p>\n<p><a href=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-41.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-684\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-41.png\" alt=\"chrome version 41\" width=\"272\" height=\"72\" \/><\/a><\/li>\n<\/ul>\n<p>Here is an easy-to-follow chart that shall help you understand the result of the browser-SSL interaction under Google&#8217;s new policies:<\/p>\n<table class=\"tg\">\n<tbody>\n<tr>\n<th class=\"tg-031e\"><\/th>\n<th class=\"tg-031e\">Example Dates<\/th>\n<th class=\"tg-031e\"><\/th>\n<th class=\"tg-031e\"><\/th>\n<th class=\"tg-031e\"><\/th>\n<th class=\"tg-031e\"><\/th>\n<\/tr>\n<tr>\n<td class=\"tg-031e\">Chrome Beta Version Dates<\/td>\n<td class=\"tg-031e\">SHA-1<br \/>\nup to Dec 31 2015<\/td>\n<td class=\"tg-031e\">SHA-1<br \/>\nJan 1 2015 to Dec 31 2015<\/td>\n<td class=\"tg-031e\">SHA-1<br \/>\nJun 1 2016 to Dec 31 2016<\/td>\n<td class=\"tg-031e\">SHA-1<br \/>\nJan 1 2017<\/td>\n<td class=\"tg-031e\">Advisable Signature Algorithm<\/td>\n<\/tr>\n<tr>\n<td class=\"tg-031e\">Chrome Version 39 Sept 2014<\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39-error.png\" alt=\"chrome version 39 error\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\" size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<\/tr>\n<tr>\n<td class=\"tg-031e\">Chrome Version 40 Nov 2014<\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39-error.png\" alt=\"chrome version 39 error\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-40-error.png\" alt=\"chrome version 40 error\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<\/tr>\n<tr>\n<td class=\"tg-031e\">Chrome Version 41 01 2015<\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39-error.png\" alt=\"chrome version 39 error\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-39-error.png\" alt=\"chrome version 39 error\" width=\"83\" height=\"83\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/chrome-version-41-error.png\" alt=\"chrome version 41 error\" width=\"80\" height=\"93\" \/><\/td>\n<td class=\"tg-031e\"><img decoding=\"async\" class=\"size-full wp-image-490\" src=\"https:\/\/www.rapidsslonline.com\/blog\/wp-content\/uploads\/2014\/10\/SSL-certificate-pad-lock.png\" alt=\"SSL certificate pad lock\" width=\"83\" height=\"83\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Understand SHA-1 Algorithm Weakness As Per Google Standards The software giant Google\u00a9 has made a crucial decision about deprecating SHA-1 signature algorithm in their extremely popular Chrome browser in order &hellip; <span class=\"d-flex justify-content-end\"><a href=\"https:\/\/www.rapidsslonline.com\/blog\/google-exclude-sha-1-upcoming-chrome-browsers\/\" class=\"btn btn-blue\">Read More <span class=\"screen-reader-text\">Google to Exclude SHA-1 in the Upcoming Chrome Browsers<\/span><\/a><\/span><\/p>\n","protected":false},"author":10,"featured_media":675,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[14],"tags":[],"yst_prominent_words":[1049,966,1039,956,834,1973,1974,981,914,1972,909,930,884,870,1063,898,886,1975,46,937],"class_list":["post-681","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ssl-certificate"],"_links":{"self":[{"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/posts\/681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/comments?post=681"}],"version-history":[{"count":0,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/posts\/681\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/media\/675"}],"wp:attachment":[{"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/media?parent=681"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/categories?post=681"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/tags?post=681"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/blog\/wp-json\/wp\/v2\/yst_prominent_words?post=681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}