[ 
https://issues.apache.org/jira/browse/SOLR-14649?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17157423#comment-17157423
 ] 

Ishan Chattopadhyaya commented on SOLR-14649:
---------------------------------------------

I just wanted to have this go out asap so that package authors can immediately 
make a switch, before it is late (and many people have started using this 
already). I'm specially concerned about Yasa adoption and DIH adoption. There's 
SOLR-14593 as well, which could go into such a release. However, I don't mind 
waiting till 8.7 as well.

> Package manager should use SHA512, not SHA1
> -------------------------------------------
>
>                 Key: SOLR-14649
>                 URL: https://issues.apache.org/jira/browse/SOLR-14649
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Ishan Chattopadhyaya
>            Priority: Major
>
> Due to a massive oversight, we only support SHA1 based package signing. We 
> should immediately switch to SHA512. Post that, all existing packages must be 
> re-signed with SHA512.
> I'll propose this for a 8.6.1 breakfix release.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to