[ https://issues.apache.org/jira/browse/SOLR-14649?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17157423#comment-17157423 ]
Ishan Chattopadhyaya commented on SOLR-14649: --------------------------------------------- I just wanted to have this go out asap so that package authors can immediately make a switch, before it is late (and many people have started using this already). I'm specially concerned about Yasa adoption and DIH adoption. There's SOLR-14593 as well, which could go into such a release. However, I don't mind waiting till 8.7 as well. > Package manager should use SHA512, not SHA1 > ------------------------------------------- > > Key: SOLR-14649 > URL: https://issues.apache.org/jira/browse/SOLR-14649 > Project: Solr > Issue Type: Improvement > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Ishan Chattopadhyaya > Priority: Major > > Due to a massive oversight, we only support SHA1 based package signing. We > should immediately switch to SHA512. Post that, all existing packages must be > re-signed with SHA512. > I'll propose this for a 8.6.1 breakfix release. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org