You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@solr.apache.org by "Jan Høydahl (Jira)" <ji...@apache.org> on 2021/08/19 09:09:00 UTC

[jira] [Commented] (SOLR-14649) Package manager should use SHA512, not SHA1

    [ https://issues.apache.org/jira/browse/SOLR-14649?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17401559#comment-17401559 ] 

Jan Høydahl commented on SOLR-14649:
------------------------------------

So what is the plan here? To switch to SHA512 in 9.0? Would make sense as most packages will need to be re-released for 9.x anyway.

> Package manager should use SHA512, not SHA1
> -------------------------------------------
>
>                 Key: SOLR-14649
>                 URL: https://issues.apache.org/jira/browse/SOLR-14649
>             Project: Solr
>          Issue Type: Improvement
>          Components: Plugin system
>            Reporter: Ishan Chattopadhyaya
>            Priority: Critical
>
> Due to a massive oversight, we only support SHA1 based package signing. We should immediately switch to SHA512. Post that, all existing packages must be re-signed with SHA512.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@solr.apache.org
For additional commands, e-mail: issues-help@solr.apache.org