Details
-
Improvement
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
3.2.7
-
None
Description
Apache is asking to remove MD5 checksums from releases.
Old policy:
- MUST provide a MD5-file
- SHOULD provide a SHA-file [SHA-512 recommended]
New policy:
- MUST provide a SHA- or MD5-file
- SHOULD provide a SHA-file
- SHOULD NOT provide a MD5-file
Providing MD5 checksum files is now discouraged for new releases, but still allowed for past releases.
Why this change:
- MD5 is broken for many purposes ; we should move away from it.
https://en.wikipedia.org/wiki/MD5#Overview_of_security_issues
Impact for PMCs:
- for new releases:
- please do provide a SHA-file (one or more, if you like)
- do NOT provide a MD5-file