SHA-1 checksums to be replaced with something better at https://gnupg.org/download/integrity_check.html ?

Daniel Villarreal youcanlinux at gmail.com
Thu Mar 17 19:01:59 CET 2016


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Any idea when you'll replace the SHA-1 checksums at the following page?

https://gnupg.org/download/integrity_check.html
List of SHA-1 check-sums
For your convenience, all SHA-1 check-sums available for software that
can be downloaded from our site, have been gathered below.


Debian und Ubuntu vertrauen SHA1 nicht mehr
http://www.pro-linux.de/news/1/23358/debian-und-ubuntu-vertrauen-sha1-ni
cht-mehr.html

Dropping SHA-1 support in APT
https://juliank.wordpress.com/2016/03/14/dropping-sha-1-support-in-apt/

Clarifications and updates on APT + SHA1
https://juliank.wordpress.com/2016/03/15/clarifications-and-updates-on-a
pt-sha1/
"...note that SHA1 support is not dropped, we merely do not consider it
trustworthy."

thanks!
- -- 
Daniel Villarreal
http://www.youcanlinux.org
youcanlinux at gmail.com
PGP key 2F6E 0DC3 85E2 5EC0 DA03  3F5B F251 8938 A83E 7B49
https://pgp.mit.edu/pks/lookup?op=get&search=0xF2518938A83E7B49

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJW6vEUAAoJEPJRiTioPntJmhcH/jbN1sZAnW0axoZjKrCRja8v
m7zn8VUGEFsFgRvleNfnT87u2xm2qQuG/+aSn7bjnUAxvl/zL+6Qs3BAnMZ3lKon
Blkh10zkr8kR5pO0nu+ai02cB5Q874dWsNMdokc/LgOP6g6c8Azuzin2YkuPFNbs
iyyYJ+yhr6RziF4Fl0vceuCTOrECLnXstMQxF8o9dzzeFuTmEcIBZ8lfu8/Dhcbo
vXk7E/xgoPry514aQdIZsMPoYKUYwfCbWhCObHvP6Nb4HEVUqHUJl/YpGwCiwebi
qJq/9YusweH47bkdz2ZeHMxwCYV7vT+d2bIVgpA8pyazw8oblNuy8fy03fo2dC0=
=Actz
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list