From 04a545827c8a7ad4c25a3478eb5094dfddfcca48 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tobias=20Nie=C3=9Fen?= Date: Tue, 29 Mar 2022 23:52:13 +0200 Subject: [PATCH] doc: guide towards x509.fingerprint256 Recommend using x509.fingerprint256 instead of x509.fingerprint and x509.fingerprint512 and suggest using it instead of x509.serialNumber in order to uniquely identify certificates. --- doc/api/crypto.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/doc/api/crypto.md b/doc/api/crypto.md index ff35c136d8a9c9..2de0fb82347fcb 100644 --- a/doc/api/crypto.md +++ b/doc/api/crypto.md @@ -2627,6 +2627,10 @@ added: v15.6.0 The SHA-1 fingerprint of this certificate. +Because SHA-1 is cryptographically broken and because the security of SHA-1 is +significantly worse than that of algorithms that are commonly used to sign +certificates, consider using [`x509.fingerprint256`][] instead. + ### `x509.fingerprint256`