[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian derivatives census: timeline for dropping SHA-1 support from apt



On Wed, Mar 16, 2016 at 8:51 AM, peter green wrote:

> My name was in the to list yet I see no mention of sha1 in
> http://deriv.debian.net/Raspbian/check-package-list and when I look at
> release.gpg I don't see any "Hash:" I just see

The Hash: SHA1 is in the InRelease files:

https://archive.raspbian.org/raspbian/dists/testing/InRelease

The Raspbian Release.gpg files use SHA1 too:

$ curl --silent
https://archive.raspbian.org/raspbian/dists/testing/Release.gpg | gpg
--list-packets | grep digest
        digest algo 2, begin of digest 07 83
$ curl --silent
https://archive.raspbian.org/raspbian/dists/testing/Release.gpg | hot
dearmor | hot dump | grep SHA-1
...
signature v4: binary RSA SHA-1 ...

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


Reply to: