Get the latest tech news
Fedora 41 Will Make OpenSSL Distrust SHA1 Signatures By Default
A change proposal has been approved for Fedora 41 to make OpenSSL distrust SHA1 signatures by default.
There seems to be a consensus that the change has to be done sooner or later, but Fedora is a remarkably conservative distribution when it comes to deprecating legacy cryptography, even if by-default-only. The decision to discover code reliant on SHA-1 signatures by blocking creation/verification has not gathered many fans, but it's not like many viable alternative proposals have been raised in return either. Opt-in logging through USDT probes has been implemented the last time and has been reinstated again to aid testing this change.
Or read this on Phoronix