Slashdot Mirror


Windows 7 Users: You Need SHA-2 Support or No Windows Updates After July 2019 (zdnet.com)

Windows 7 and Windows Server 2008 users need to have SHA-2 code-signing installed by July 16, 2019, in order to continue to get Windows updates after that date. Microsoft issued that warning on February 15 via a Support article. From a report: Windows operating system updates are dual-signed using both the SHA-1 and SHA-2 hash algorithms to prove authenticity. But going forward, due to "weaknesses" in SHA-1, Microsoft officials have said previously that Windows updates will be using the more secure SHA-2 algorithm exclusively. Customers running Windows 7 SP1, Windows Server 2008 R2 SP1 and Windows Server 2008 SP2 must have SHA-2 code-signing support installed by July 2019, Microsoft officials have said.

3 of 146 comments (clear)

  1. Great Clickbait by Anonymous Coward · · Score: 5, Informative

    Why don't we read the next blurbs of the article that come immediately after the part cited in the summary:

    "Microsoft has published a timeline for migrating these operating systems to SHA-2, with support for the algorithm coming in standalone updates. On March 12, Microsoft is planning a standalone update with SHA-2 code sign support for Windows 7 SP1 and Windows Server 2008 R2 SP1. It also will deliver to WSUS 3.0 SP2 the required support for delivering SHA-2 updates.

    Microsoft will make available a standalone update with SHA-2 code sign support for Windows Server 2008 SP2 on April 9, 2019. "

    tldr; nothing will change for these users

  2. Re:Microsoft : You must update to have updates by Stormwatch · · Score: 5, Informative

    As much as I like Linux, Windows is still where all the games are.

  3. Old patch already addressed this by Anonymous Coward · · Score: 2, Informative

    There is an old patch for windows7 that already added SHA2 code signing: KB3033929. It can still be downloaded directly from microsoft.com without having to enable updates.