Removing SHA-1 for signatures in Fedora
Removing SHA-1 for signatures in Fedora
Posted Mar 16, 2022 17:48 UTC (Wed) by hkario (subscriber, #94864)In reply to: Removing SHA-1 for signatures in Fedora by khim
Parent article: Removing SHA-1 for signatures in Fedora
That's because the behaviour of the symbols isn't changing to make developers lives easier.
It's changing because with the exception of verifying signatures you can prove were made way, way back, you should really not trust SHA-1 signatures.
It's changing because with the exception of verifying signatures you can prove were made way, way back, you should really not trust SHA-1 signatures.
It doesn't matter if my mail client was compiled 10 years ago, I don't want it to trust SHA-1 signatures today because they could have been forged yesterday.
The other problem is that the RHEL-9 change doesn't remove SHA-1 hash, or any symbols associated with it, it forbids the combination of SHA-1 and public key cryptography.
