<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>23139</bug_id>
          
          <creation_ts>2013-09-03 14:24:40 +0000</creation_ts>
          <short_desc>MD5 is only message digest algorithm mentioned for keygen field</short_desc>
          <delta_ts>2016-04-22 18:01:00 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>HTML5 spec</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>MOVED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>editorial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="JK">j.kewley</reporter>
          <assigned_to name="This bug has no owner yet - up for the taking">dave.null</assigned_to>
          <cc>arronei</cc>
    
    <cc>mathias</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-admin</cc>
    
    <cc>public-html-wg-issue-tracking</cc>
    
    <cc>robin</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>92880</commentid>
    <comment_count>0</comment_count>
    <who name="JK">j.kewley</who>
    <bug_when>2013-09-03 14:24:40 +0000</bug_when>
    <thetext>I was looking at HTML 5.1 Nightly, 4.10.14 The keygen element
http://www.w3.org/html/wg/drafts/html/master/forms.html#the-keygen-element

It states
----
If the keytype attribute is in the RSA state
    Generate an RSA key pair using the settings given by the user, if appropriate, using the md5WithRSAEncryption RSA signature algorithm (the signature algorithm with MD5 and the RSA encryption algorithm) referenced in section 2.2.1 (&quot;RSA Signature Algorithm&quot;) of RFC 3279, and defined in RFC 2313. [RFC3279] [RFC2313]
---

Should SHA1 (or even SHA256 or other &quot;SHA2&quot; algorithms) not be mentioned at least as an alternative? While MD5 should be fine for requests, I understand that support is moving away from it towards the SHA algorithms.

Or have I misunderstood the importance of this above statement?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>92881</commentid>
    <comment_count>1</comment_count>
    <who name="Robin Berjon">robin</who>
    <bug_when>2013-09-03 14:33:19 +0000</bug_when>
    <thetext>Last I checked there was very little interest (pretty much none) in evolving keygen. The plan was that additions to this part of the platform would happen in the Web Crypto APIs. As such, I believe that the algorithm just describes the reality of what is implemented, and that there are no plans to enhance that.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>126050</commentid>
    <comment_count>2</comment_count>
    <who name="Arron Eicholz">arronei</who>
    <bug_when>2016-04-22 18:01:00 +0000</bug_when>
    <thetext>HTML5.1 Bugzilla Bug Triage: Moved the discussion is now happening in the github issue [1]. Please continue the discussion on that issue if you feel this item has not been fully addressed. Thanks!

[1] - https://github.com/w3c/html/issues/43</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>