Skip to content
GitLab
  • Explore
  • Sign in
  • The Tor Project
  • TPA
  • TPA teamTPA team
  • Issues
  • #9811

use sha256 or sha512 instead of sha1 for deb.torproject.org

For example http://deb.torproject.org/torproject.org/dists/tor-0.2.4.x-jessie/InRelease currently uses Hash: SHA1. Please use a stronger hash, such as sha256 or sha512.

I believe, if you add

personal-digest-preferences SHA512
cert-digest-algo SHA512
default-preference-list SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 ZLIB BZIP2 ZIP Uncompressed

to ~/.gnupg/gpg.conf that should do the trick.

Otherwise try "gpg --edit-key your@mail", setpref, SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 ZLIB, save.

Assignee
Assign to
Time tracking