> On 16. Mar 2022, at 00:04, Tom Hughes via devel 
> <devel@lists.fedoraproject.org> wrote:
> 
> On 15/03/2022 22:45, Robert Relyea wrote:
> 
>> 1) in fedora 37, provide a policy that turns SHA-1 off. in our testing, we 
>> encourage people to run with that policy and write bugs against components.
> 
> That policy already exists in Fedora 34 and 35 where the FUTURE policy
> does not allow SHA1 in signature algorithms.

In the case of OpenSSL, that only affects use of SHA1 as signature algorithms 
in TLS.
It does not cover arbitrary signatures with a SHA1 digest, which is what we are 
proposing.


HTH,
Clemens

-- 
Clemens Lang
RHEL Crypto Team
Red Hat


_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to