Get the latest tech news

Fedora 41 Will Make OpenSSL Distrust SHA1 Signatures By Default


A change proposal has been approved for Fedora 41 to make OpenSSL distrust SHA1 signatures by default.

There seems to be a consensus that the change has to be done sooner or later, but Fedora is a remarkably conservative distribution when it comes to deprecating legacy cryptography, even if by-default-only. The decision to discover code reliant on SHA-1 signatures by blocking creation/verification has not gathered many fans, but it's not like many viable alternative proposals have been raised in return either. Opt-in logging through USDT probes has been implemented the last time and has been reinstated again to aid testing this change.

Get the Android app

Or read this on Phoronix

Read more on:

Photo of default

default

Photo of fedora

fedora

Related news:

News photo

Fedora 41 Installer Proceeding To Transition From X11 To Wayland App

News photo

Fedora has been shipping with a broken screen reader for nine years

News photo

WhatsApp finally lets you send HD photos and videos by default