Skip to content

Conversation

@xnox
Copy link

@xnox xnox commented Dec 19, 2025

To comply with complete withdrawal of SHA1 usage by both IETF RFC
(non-fips) and NIST CMPV (fips) by 2030, stop producing SHA1 and MD5
checksum files in favor of only providing SHA256 checksum files.

As we enter 2026, software produced today might be in active use in
2030 hence it is best to be forward looking with this.

If anything breaks, this can be reverted with a migration plan figured
out to be executed by 2030.

…e SHA256 files

To comply with complete withdrawal of SHA1 usage by both IETF RFC
(non-fips) and NIST CMPV (fips) by 2030, stop producing SHA1 and MD5
checksum files in favor of only providing SHA256 checksum files.

As we enter 2026, software produced today might be in active use in
2030 hence it is best to be forward looking with this.

If anything breaks, this can be reverted with a migration plan figured
out to be executed by 2030.
@kelly-cs
Copy link
Contributor

kelly-cs commented Jan 9, 2026

Thanks for flagging, @xnox.

I've created a SERVER ticket to track this. This might need some additional changes/attention so I'm going to close this and have follow-up discussion on that ticket.

@kelly-cs kelly-cs changed the title evergreen: y2030 - stop producing SHA1 and MD5 files, and only provide SHA256 files SERVER-116465: evergreen: y2030 - stop producing SHA1 and MD5 files, and only provide SHA256 files Jan 9, 2026
@kelly-cs kelly-cs closed this Jan 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants