[ https://issues.apache.org/jira/browse/SOLR-14649?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17157388#comment-17157388 ]
Ishan Chattopadhyaya commented on SOLR-14649: --------------------------------------------- This is not an immediate danger, because: # Breaking SHA1 is still prohibitively expensive: https://wccftech.com/google-cracked-sha1/ # Not many packages are out there However, because adoption is still low, it is the right time to fix this. > Package manager should use SHA512, not SHA1 > ------------------------------------------- > > Key: SOLR-14649 > URL: https://issues.apache.org/jira/browse/SOLR-14649 > Project: Solr > Issue Type: Improvement > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Ishan Chattopadhyaya > Priority: Major > > Due to a massive oversight, we only support SHA1 based package signing. We > should immediately switch to SHA512. Post that, all existing packages must be > re-signed with SHA512. > I'll propose this for a 8.6.1 breakfix release. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org