Breaks listing or upgrading SHA-1 RPMs
Breaks listing or upgrading SHA-1 RPMs
Posted Mar 23, 2022 6:41 UTC (Wed) by AdamW (subscriber, #48457)In reply to: Breaks listing or upgrading SHA-1 RPMs by rwmj
Parent article: Removing SHA-1 for signatures in Fedora
IIRC it is possible to implement something more finely grained than just "pick DEFAULT or LEGACY" with the crypto-policies system, but it's more complicated and difficult. This again is similar to SELinux, where it's usually a much better idea to create a custom policy than just switch to permissive mode, but doing so is more than a single command so people just use the big hammer...
