SHA1 is insecure now, and is forbidden in RHEL and will be forbidden in several crypto-policies in Fedora in some future. This patch adds detection of SHA1 signatures availability and, if not available, enforces fallback to SHA2.