Removing SHA-1 for signatures in Fedora
Removing SHA-1 for signatures in Fedora
Posted Mar 16, 2022 14:27 UTC (Wed) by epa (subscriber, #39769)In reply to: Removing SHA-1 for signatures in Fedora by foom
Parent article: Removing SHA-1 for signatures in Fedora
It sounds as though the maintainer could defeat that attack by adding some random data to the commit message before signing. Or perturb the timestamp, perhaps by cherry-picking the change into a new commit, which can then be signed. That makes life more awkward for the original contributor when merging back, but only slightly.
