{"id":7760,"date":"2018-11-21T00:34:00","date_gmt":"2018-11-20T23:34:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=7760"},"modified":"2024-10-03T00:30:26","modified_gmt":"2024-10-02T22:30:26","slug":"windows-7-from-april-2019-sha-2-support-is-required","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/11\/21\/windows-7-from-april-2019-sha-2-support-is-required\/","title":{"rendered":"Windows 7: From April 2019 &lsquo;SHA-2-Support&rsquo; is required"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"win7\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/03\/win7_thumb1.jpg\" alt=\"win7\" width=\"44\" height=\"42\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/?p=211955\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Users of Windows 7 SP1 (and its server counterparts) and WSUS will need a special update from April 2019, which will enable the machine to handle SHA2 code signatures. Without this update, these machines can no longer process updates.<\/p>\n<p><!--more--><\/p>\n<h2>Background: Switching to SHA-2<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/357630326a134f21b0e5363e7cde06e4\" alt=\"\" width=\"1\" height=\"1\" \/>Updates for Windows are dual-signed using both the SHA-1 and SHA-2 hash algorithms to authenticate that updates come directly and unmodified from Microsoft. Due to weaknesses in the SHA-1 algorithm and to align to industry standards Microsoft will only sign Windows updates using the more secure SHA-2 algorithm exclusively.<\/p>\n<h2>SHA-2 required from 2019 onwards (Windows, WSUS)<\/h2>\n<p>In a 2019 support post, <a href=\"https:\/\/web.archive.org\/web\/20201231202502\/https:\/\/support.microsoft.com\/en-us\/help\/4472027\/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus\" target=\"_blank\" rel=\"noopener noreferrer\">2019 SHA-2 Code Signing Support requirement for Windows and WSUS<\/a> Microsoft has now announced changes in the code signing for Windows updates for 2019. The protection of Windows updates with two hash values (SHA-1 and SHA-2) will expire in 2019. Due to weaknesses in the SHA-1 algorithm and to align to industry standards, Microsoft will sign Windows updates only with the more secure SHA-2 algorithm.<\/p>\n<p>Customers using Windows 7 SP1, Windows Server 2008 R2 SP1, and Windows Server 2008 SP2 (and WSUS) must have SHA-2 code signing support installed on these systems by April 2019. Windows systems without SHA-2 support will no longer be eligible for Windows updates from April 2019.<\/p>\n<p>To prepare machines for this change, Microsoft 2019 will release appropriate updates to SHA-2 support. Some older versions of Windows Server Update Services (WSUS) will also receive SHA-2 support to properly deploy SHA-2-signed updates.<\/p>\n<p>Support for SHA-2 will be available in the monthly updates from early 2019. The migration process to exclusive SHA-2 support will be gradual and support will be offered in multiple update packages. Only one update package with SHA-2 support may be installed to activate support. Microsoft is striving for the following schedule to provide SHA-2 support.<\/p>\n<ul>\n<li>February 2019: The operating systems mentioned above receive SHA-2 support via a stand-alone update and via the preview of the monthly rollup update. In addition, Update for SHA-2 Support for WSUS 3.0 SP2 is provided.<\/li>\n<li>March 2019: The monthly March 2019 rollup and security update includes support for SHA-2 code signing.<\/li>\n<li>April 2019: Updates for the above Windows versions require the installation of SHA-2 code signing support. Installing one of the earlier Windows updates listed above provides the support necessary to continue receiving Windows updates after April 2019.<\/li>\n<li>July 2019: Starting in July, customers using WSUS 3.0 SP2 must have SHA-2 support installed and all Windows Service updates will only be SHA-2 signed.<\/li>\n<\/ul>\n<p>Machines with Windows 8.1 and Windows 10 are not affected by this change, SHA-2 support is already integrated. (<a href=\"https:\/\/web.archive.org\/web\/20181120205400\/https:\/\/www.computerworld.com\/article\/3322518\/microsoft-windows\/heads-up-a-critical-win7-server-2008-patch-coming-in-february-march-that-s-really-critical.html\" target=\"_blank\" rel=\"noopener noreferrer\">via<\/a>)<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/02\/18\/sha-2-patch-for-windows-7-arrives-on-march-2019\/\" rel=\"bookmark\">SHA-2 patch for Windows 7 arrives on March 2019<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Users of Windows 7 SP1 (and its server counterparts) and WSUS will need a special update from April 2019, which will enable the machine to handle SHA2 code signatures. Without this update, these machines can no longer process updates.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[195,17,569],"class_list":["post-7760","post","type-post","status-publish","format-standard","hentry","category-windows","tag-update","tag-windows-7","tag-wsus"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=7760"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7760\/revisions"}],"predecessor-version":[{"id":35330,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7760\/revisions\/35330"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=7760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=7760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=7760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}