-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[build] Sign debs with sha512 #8002
Conversation
jenkins, test this |
LGTM |
LGTM |
--------- **Commit 1:** [build] Sign debs with sha512 * Original sha: 71b3f58 * Authored by Jonathan Budzenski <[email protected]> on 2016-08-15T14:34:53Z
--------- **Commit 1:** [build] Sign debs with sha512 * Original sha: 71b3f58 * Authored by Jonathan Budzenski <[email protected]> on 2016-08-15T14:34:53Z
Hi, my os is ubuntu 16.04 W: http://packages.elastic.co/kibana/4.5/debian/dists/stable/Release.gpg: Signature by key 46095ACC8548582C1A2699A9D27D666CD88E42B4 uses weak digest algorithm (SHA1) |
@cwhsu1984 This issue is fixed in 5.0.0 GA, but you need to remove the Delete or empty |
[build] Sign debs with sha512 Former-commit-id: a254b7e
Debian/ubuntu will be disabling support for release files signed with sha1 in the future, and currently a warning is shown. This makes sure the release file is signed using sha512. Closes #7992.
See https://wiki.debian.org/Teams/Apt/Sha1Removal