Ubuntu will reject SHA-1 in APT from January 2017

sha1

Today it was announced that soon, On Jan 1, 2017 Ubuntu plans to disable SHA-1 algorithm support for APT application. SHA-1 (Secure Hash Algorithm 1), is a cryptographic algorithm widely used in digital certificates that is also used as a summary function and that due to its obsolescence will affect more than one characteristic of our systems.

As expected, other distributions will also be affected, including Debian or Linux Mint, all of them having to manage how they will do a new signature of the packages that appear in their repositories.

Julian Andres, current Debian developer and Ubuntu member has announced that the current SHA-1 algorithm on which digital signatures are based on many content, including certificate revocation lists (CRLs), will no longer be valid as of January 1, 2017. This algorithm is used for signing package repositories in Debian APT (Advance Package Tool) and other distributions like Ubuntu and Linux Mint. The distributions where it will take effect from the date indicated will be Ubuntu 16.04 LTS (Xenial Xerus) and Ubuntu 16.10 (Yakkety Yak).

Canonical company's next move is speed up the APT 1.4 beta release a bit in the upcoming Ubuntu 17.04 (Zesty Zapus). Although there is still much work ahead, it is being studied whether in this distribution directly reject packages or at least display some kind of warning end to the user on this fact. When it is finished deploying in this version of APT, it will carry stable versions of APT 1.3 and APT 1.2 on Ubuntu 16.04 LTS (Xenial Xerus) and Ubuntu 16.10 (Yakkety Yak).

Por el momento Debian is expected to make a similar move regarding their distributions, while Linux Mint has not commented on the matter. There is still a reasonable amount of time to see what happens, although the process is expected to be fairly transparent and easy for the end user.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.