though given the deprecation of SHA1 in other systems I would say a SHA2 hash (using SHA1 these days is like using MD5 a couple of years back - time to move on :) ) SHA-512 because it's 64-bit based.... and less likely to have an issue with certification bodies etc etc alan