Clarification on SHA-1 (OID 1.2.840.113549.1.1.5) requirement for TLS Configuration Add-on in ODTT v25.12 #125
|
Dear ONVIF Team, While running ONVIF Device Test Tool v25.12 (rev227) for conformance testing, we observed that the TLS Configuration Add-on preliminary check still requires the device to support the signature algorithm 1.2.840.113549.1.1.5 (SHA-1 with RSA). This requirement appears in ONVIF Add-ons Conformance Device Test Specification v24.12, section 3.2, which states that if the device does not support signature algorithm 1.2.840.113549.1.1.5, it will be regarded as not supporting the ONVIF TLS Add-on. However, in ONVIF Security Service Specification v25.12, section 6 (Security Considerations), it is stated that devices should implement secure and up-to-date signature algorithms, and that supported algorithms should follow the ONVIF Security Baseline. From our understanding, the ONVIF Security Baseline does not list SHA-1 with RSA (OID 1.2.840.113549.1.1.5) as a required algorithm, since SHA-1 is generally considered deprecated due to security concerns. Therefore, we would like to clarify: Is support for OID 1.2.840.113549.1.1.5 (SHA-1 with RSA) still a mandatory requirement for claiming TLS Configuration Add-on support? Or is this check in ODTT v25.12 a legacy condition that may be removed in a future version of the test tool? We would appreciate confirmation on whether devices should still implement this algorithm for certification purposes, or if support for stronger algorithms (e.g., SHA-256 or above) is sufficient. Thank you. |
Replies: 2 comments
|
Hello, |
|
Hi, |
Hello,
We do acknowledge there is ambiguity in the implementation. We will publish an erratum for DTT v25.12 shortly to address the issue.
Thanks for your patience!