I still strongly disagree. When it comes to hashes and crypto, we should defer to the IETF PKIX WG, or have a strongly justifiable reason for doing so -- enough to convince PKIX to change. This means: MD5 should be discouraged. SHA1 results are public. Perhaps we should ask IET-PKIX folks for an opinion?