In all cases we've used the default authentication method.
My understanding was that this was originally HMAC-SHA2 and is now HMAC-SHA2-256.
If that is correct, that means that delaying the upgrade wasn't necessary; we could have just changes the authentication mode.
kmb
|