[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <176643400578.1902051.9409046385163707144.b4-ty@google.com>
Date: Mon, 22 Dec 2025 20:24:17 +0000
From: Sami Tolvanen <samitolvanen@...gle.com>
To: David Howells <dhowells@...hat.com>, David Woodhouse <dwmw2@...radead.org>,
Luis Chamberlain <mcgrof@...nel.org>, Daniel Gomez <da.gomez@...nel.org>,
Aaron Tomlin <atomlin@...mlin.com>, Petr Pavlu <petr.pavlu@...e.com>
Cc: Sami Tolvanen <samitolvanen@...gle.com>, keyrings@...r.kernel.org,
linux-modules@...r.kernel.org, linux-kernel@...r.kernel.org
Subject: Re: [PATCH 0/2] module: Remove SHA-1 support for module signing
On Tue, 11 Nov 2025 16:48:30 +0100, Petr Pavlu wrote:
> SHA-1 is considered deprecated and insecure due to vulnerabilities that can
> lead to hash collisions. Most distributions have already been using SHA-2
> for module signing because of this. The default was also changed last year
> from SHA-1 to SHA-512 in f3b93547b91a ("module: sign with sha512 instead of
> sha1 by default"). This was not reported to cause any issues. Therefore, it
> now seems to be a good time to remove SHA-1 support for module signing.
>
> [...]
Applied to modules-next, thanks!
[1/2] module: Remove SHA-1 support for module signing
commit: 148519a06304af4e6fbb82f20e1a4480e2c1b126
[2/2] sign-file: Use only the OpenSSL CMS API for signing
commit: d7afd65b4acc775df872af30948dd7c196587169
Best regards,
Sami
Powered by blists - more mailing lists