diff --git a/CertificationPracticeStatement.html b/CertificationPracticeStatement.html index 22e443a..e6ad9fc 100755 --- a/CertificationPracticeStatement.html +++ b/CertificationPracticeStatement.html @@ -2961,7 +2961,9 @@ No limitation is placed on Subscriber key sizes.

CAcert X.509 root and intermediate keys are currently 4096 bits. X.509 roots use RSA and sign with the SHA-1 message digest algorithm. +Certificates have been signed until 2004 with MD5, since 2005 SHA-1 or better algorithms are used. See §4.3.1. +

@@ -2974,15 +2976,6 @@ in line with general cryptographic trends, and as supported by major software suppliers.

- - -

6.1.6. Public key parameters generation and quality checking