On 19/05/16 03:17, Paul Wise wrote: > On Wed, May 18, 2016 at 9:20 PM, Daniel Pocock wrote: > >> Can anybody comment on how Debian users will be impacted by SHA-1 >> deprecation? > > There is some info related to that in these two wiki pages: > > https://wiki.debian.org/SHA-1
The way that page is structured today, it mixes things about how SHA-1 is used in Debian infrastructure (e.g. for the SPI CA) and how it is used in some of the software we distributed (e.g. in Git) Maybe we need to break it into separate sections: - SHA-1 in Debian infrastructure and workflows - SHA-1 in Debian packages Are there any useful discussions about the deprecation of MD-5 that we could link to, to give people an understanding of how things will change or how they should change? > https://wiki.debian.org/Teams/Apt/Sha1Removal >