Package: coreutils
Version: 5.2.1-2
Severity: wishlist

md5 has been broken for some time now; sha1 also has been, more
recently (an actual collision is not known, so far, but a way to
produce one in a "reasonable" amount of computer time has been
provided).  Consequently, the md5sum and sha1sum utilities should be
deprecated for most security-sensitive uses.

sha256, sha384 and sha512 are the generally advocated replacements.
They should be made available in coreutils (certainly there are other
implementations available, but it is essential that they be at least
as widely available as md5sum was, if they are to replace it).

So, please implement sha256sum, sha384sum and sha512sum as part of
coreutils, either in Debian or by forwarding upstream.  I can provide
a patch for this if it is useful.

-- 
     David A. Madore
    ([EMAIL PROTECTED],
     http://www.madore.org/~david/ )


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to