This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 20 · May 12 – 18, 2025

crypto/tls: disable SHA-1 signature algorithms in TLS 1.2

Breakingstdlib

What changed
Support for the SHA‑1 signature algorithms rsa_pkcs1_sha1 and ecdsa_sha1 is removed from TLS 1.2. A GODEBUG=tlssha1=1 flag can restore the old behavior.
Production impact
Any service that relies on TLS 1.2 with SHA‑1 signatures will fail to negotiate a connection unless the flag is set.
Try it
Run a TLS client with GODEBUG=tlssha1=1 and observe that SHA‑1 signatures are accepted again.
Source
github.com/golang/go/issues/72883

Understand it, then run it

TLS 1.2 still allowed certificates signed with the old SHA‑1 hash. The change removes that support. Now a TLS 1.2 connection will refuse to use a certificate that was signed with SHA‑1. If a server still uses such a certificate, clients will fail to connect unless the special GODEBUG=tlssha1=1 flag is set to re‑enable the old behaviour.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed