SHA-1 deprecation timeline

Robert J. Hansen rjh at sixdemonbag.org
Tue May 10 22:00:13 CEST 2016


> What is the current plan for the complete deprecation of SHA-1 from GnuPG?

There isn't one.  GnuPG tracks the IETF OpenPGP RFC.  Once they
deprecate SHA-1, GnuPG will follow suit probably within a couple of
weeks.  However, until then, SHA-1 stays.

If your next question is "What's the working group's plan for complete
deprecation of SHA-1?", they're currently hammering out a major overhaul
to the RFC.  There is no timetable yet, but it's an area of active
development.

Hope this helps!



More information about the Gnupg-devel mailing list