On Fri, 24 Aug 2018, Bill Cole wrote:

On 24 Aug 2018, at 19:24, John Hardin wrote:

How far back does the SHA256 support go?

Not far:

                $ svn log sa-update.raw  |grep -A1 -B3 SHA256
                
------------------------------------------------------------------------
r1826916 | billcole | 2018-03-15 23:15:19 -0400 (Thu, 15 Mar 2018) | 1 line

added optional support for SHA256 in addition to or instead of SHA1 validation
                
------------------------------------------------------------------------


Would 3.3.x or 3.4.0 be broken by dropping the SHA1 sigs?

Yes. 3.4.1 as well.

Rats.

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 jhar...@impsec.org    FALaholic #11174     pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  A sword is never a killer, it is but a tool in the killer's hands.
                          -- Lucius Annaeus Seneca (Martial) 4BC-65AD
-----------------------------------------------------------------------
 Today: the 1939th anniversary of the destruction of Pompeii

Reply via email to