SHA-1 deprecation timeline

Robert J. Hansen rjh at
Tue May 10 22:00:13 CEST 2016

> What is the current plan for the complete deprecation of SHA-1 from GnuPG?

There isn't one.  GnuPG tracks the IETF OpenPGP RFC.  Once they
deprecate SHA-1, GnuPG will follow suit probably within a couple of
weeks.  However, until then, SHA-1 stays.

If your next question is "What's the working group's plan for complete
deprecation of SHA-1?", they're currently hammering out a major overhaul
to the RFC.  There is no timetable yet, but it's an area of active

Hope this helps!

More information about the Gnupg-devel mailing list