[ 
https://issues.apache.org/jira/browse/SOLR-14649?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17157691#comment-17157691
 ] 

Robert Muir commented on SOLR-14649:
------------------------------------

Hi [~ichattopadhyaya], I don't know the big picture on how this package manager 
works. How is this hashing used? How are the packages signed?

> Package manager should use SHA512, not SHA1
> -------------------------------------------
>
>                 Key: SOLR-14649
>                 URL: https://issues.apache.org/jira/browse/SOLR-14649
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Ishan Chattopadhyaya
>            Priority: Major
>
> Due to a massive oversight, we only support SHA1 based package signing. We 
> should immediately switch to SHA512. Post that, all existing packages must be 
> re-signed with SHA512.
> I'll propose this for a 8.6.1 breakfix release.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to