The developers of Arch Linux have warned users that starting from the update of the libxcrypt package 4.4.21, the use of vulnerable password hashing schemes such as MD5 and SHA1 will be prohibited when specifying new passwords in the distribution. For accounts where MD5 and SHA1 hashes are already used for password verification, a warning will be displayed suggesting the user update their password when attempting to log in.
Source: opennet.ru