Radar · Go · Archive · Week 20 · May 12 – 18, 2025
crypto/tls: disable SHA-1 signature algorithms in TLS 1.2
Breakingstdlib
- What changed
- Support for the SHA‑1 signature algorithms
rsa_pkcs1_sha1andecdsa_sha1is removed from TLS 1.2. AGODEBUG=tlssha1=1flag can restore the old behavior. - Production impact
- Any service that relies on TLS 1.2 with SHA‑1 signatures will fail to negotiate a connection unless the flag is set.
- Try it
- Run a TLS client with
GODEBUG=tlssha1=1and observe that SHA‑1 signatures are accepted again. - Source
- github.com/golang/go/issues/72883
Understand it, then run it
TLS 1.2 still allowed certificates signed with the old SHA‑1 hash. The change removes that support. Now a TLS 1.2 connection will refuse to use a certificate that was signed with SHA‑1. If a server still uses such a certificate, clients will fail to connect unless the special GODEBUG=tlssha1=1 flag is set to re‑enable the old behaviour.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed