What is the SHA1 file format?
.SHA1 is a plain-text checksum sidecar file that stores one or more SHA-1 cryptographic digests alongside their corresponding filenames. Its format follows the GNU sha1sum convention: each line contains a 40-character lowercase hexadecimal digest (representing 160 bits / 20 bytes), a two-space separator (or * for binary mode), and the filename.
SHA-1 was published by NIST in April 1995 (FIPS 180-1) and became a standard integrity-verification tool for software distribution throughout the late 1990s and 2000s. A .sha1 sidecar allows a user to verify a downloaded file has not been corrupted - by running sha1sum -c file.sha1 on Linux/macOS or certutil -hashfile / Get-FileHash -Algorithm SHA1 on Windows.
Important: SHA-1 is cryptographically broken. Google and CWI Amsterdam demonstrated a practical collision attack (*SHAttered*) in February 2017, proving two different files can produce the same digest. NIST had already deprecated SHA-1 for security use in 2011. .sha1 files remain useful for detecting accidental corruption (bit-rot), but must not be relied upon to verify authenticity or detect deliberate tampering. For security purposes, .sha256 or .sha512 are strongly preferred.
SHA-1 remains in widespread use in Git for object hashing; newer Git repository formats are actively migrating to SHA-256.
Security & safety
RISK: LOWThe .sha1 file itself is harmless plain text. The security concern is what SHA-1 guarantees: it reliably detects accidental corruption (bit-flip, truncated download) but is cryptographically broken since the 2017 SHAttered collision attack. A matching SHA-1 does NOT prove a file was not deliberately replaced. For security-sensitive downloads (OS images, signed software), verify a SHA-256 or SHA-512 checksum AND the publisher's PGP/GPG signature. Ensure the published hash comes from a trusted HTTPS source, not the same server as the file.
Format details
in a nutshellPrograms that open SHA1 files
Technical details
deep spec| Digest algorithm | SHA-1 (Secure Hash Algorithm 1), FIPS 180-1 / FIPS 180-4 |
| Digest length | 160 bits (20 bytes), represented as 40 lowercase hexadecimal characters per hash |
| File encoding | Plain ASCII text (UTF-8 for filenames containing non-ASCII characters) |
| Line format | <40-char hex> <filename> (two-space separator, text mode); <40-char hex> *<filename> (binary mode) |
| Command-line compatibility | GNU sha1sum -c (Linux/macOS); certutil -hashfile (Windows); Get-FileHash -Algorithm SHA1 (PowerShell) |
| Container | None - plain text file, no binary wrapper |
| Typical file size | Under 1 KB (single-file sidecar); a few KB for multi-file manifests |
| Security status | Cryptographically broken - SHAttered collision demonstrated February 2017 (Google / CWI Amsterdam) |
| NIST deprecation | Deprecated for security use since 2011; SHA-1 TLS certificates distrusted by major browsers since 2017 |
| Remaining valid use | Accidental corruption detection (bit-rot) in non-adversarial contexts; Git object hashing (legacy SHA-1 mode) |
| Preferred replacement | SHA-256 (.sha256) or SHA-512 (.sha512) per NIST SP 800-131A |
| Released | SHA-1 published April 1995 (FIPS 180-1); .sha1 sidecar convention in common use since late 1990s |
| Latest version | FIPS 180-4 (2015) - no versioned file format; format is a convention |
| Open standard | Yes · royalty-free |
| Specification | csrc.nist.gov |
SHA1 conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about SHA1 files.