Skip to content

Deprecated SHA-1 is used for checksums #467

Closed
@dholbach

Description

@dholbach

Found by Ada Logics:

In the storage utility of the source controller checksums on the collected artifacts are calculated using SHA-1. SHA-1 is considered deprecated as collision attacks against SHA-1 are feasible.

Switch from SHA-1 to SHA-2 in checksum calculations.

We want to emphasize here that it is only in the checksum calculation SHA-1 is recommended not to be used. In the HMAC implementation of Flux SHA-1 is still safe to use.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions