-
-
Notifications
You must be signed in to change notification settings - Fork 94
Open
Description
Currently, the key used to sign the repository is still using SHA1 as algorithm. This algorithm has been declared obsolete/insecure for quite some time now.
Although the documentation on installation on RedHat/Rocky/CentOS clearly states that the OS needs to be modified to accept SHA1-based encryption, I would prefer to not modify such a high security setting of the OS.
Please sign the repository and the packages using a newer GPG key that uses an up-to-date algorithm.
I have seen a comment in another ticket that version 4.x is around the corner, this might be a good time to include this change as well?
Metadata
Metadata
Assignees
Labels
No labels