https://bz.apache.org/bugzilla/show_bug.cgi?id=62530
--- Comment #1 from Luca Toscano ---
Hi,
when you say "deprecated" you mean generically or by the Apache foundation? It
is pretty clear in the documentation that the verification is done via PGP and
not MD5, but I agree with you that it might
https://bz.apache.org/bugzilla/show_bug.cgi?id=62530
--- Comment #2 from Christophe JAILLET ---
Luca: reference is http://www.apache.org/dev/release-distribution#sigs-and-sums
You can also find some discussion about it on the private@ ML.
Mails are dated 2018-08-17 14:18, and 2018-03-05 11:18.