Comment 6 for bug 1883271

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

This is now causing active pain.

For FIPS certifcation of Ubuntu libraries we had to re-implement and re-add md5 with a usage indicator that it is not certified for use. Which costs us development time, and delays in submitting Ubuntu 22.04 for FIPS certification.

Separately sha1 has been deprecated by NIST and purchasing software that uses sha1 will be prohibited in 2030.

This is sort of already within the lifetime of Jammy.

Please remove MD5 and SHA1 from all currently supported Ubuntu Archive releases, as all of them support better hashes.