6eeb2f2963
SHA1 has been getting a bit long in the tooth for many years by now, add a more modern digest to eventually supplant it, for now just prefer SHA256 over SHA1 if present when verifying. Using a hardwired algorithm instead of configurable one to keep things on the simple side when dealing with the signature header. Signing could add the new digest for older packages but we don't do that to avoid surprises when people are signing older packages. |
||
---|---|---|
.. | ||
Makefile.am | ||
rpmgensig.c | ||
rpmsign.h |