> My opinion is that SHA1 should no longer be used.

Of course in the best of worlds it shouldn't be used anymore. But if
everyone started signing their emails with SHA1 I couldn't be more
pleased, because then you at least have the infrastructure in place, and
can upgrade people later. The major problem we're facing is that we
can't even get most people to use MD5 or DES. Heck, they don't even know
who or what they are, and to be frank they shouldn't have to.


