forked from git/git
-
Notifications
You must be signed in to change notification settings - Fork 2.7k
Closed as not planned
Description
The release notes of openssh 8.8, which is shipped with this version, say:
This release disables RSA signatures using the SHA-1 hash algorithm by default. This change has been made as the SHA-1 hash algorithm is cryptographically broken, and it is possible to create chosen-prefix hash collisions for <USD$50K [1]
Our (internal) Git servers still use this algorithm, so we can not connect to any of them with this version of Git. This is the default key that is created by Gerrit, even on version 3.4, which is the latest stable (it was replaced and then reverted).
If you consider this upgrade necessary, please at least postpone it for a major release.
alchemistmatt, slavonnet, burakgok, solverit, bnm22 and 2 morekenyon, tiger040988 and lavinia8
Metadata
Metadata
Assignees
Labels
No labels