GitHub Permanently Disables SHA-1 for HTTPS and TLS Connections from Sept 15
GitHub disabled SHA-1 support for HTTPS and TLS on github.com and its CDNs on September 15, 2026, ending years of legacy compatibility. The company had signaled the change since April 2026 and conducted an 18-hour brownout on July 14 to alert affected users before the final cutoff. Clients unable to complete a TLS handshake without SHA-1 now receive a connection error when accessing GitHub. The change affects github.com, GitHub Enterprise Cloud, and partner CDNs, but does not impact self-hosted GitHub Enterprise Server installations. Most failures have been traced to outdated infrastructure such as old curl builds, unpatched .NET Framework versions, and stale Docker base images rather than end-user browsers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in