David Handermann created NIFI-8132:
--------------------------------------
Summary: Replace Framework Uses of MD5 with Modern Algorithm
Key: NIFI-8132
URL: https://issues.apache.org/jira/browse/NIFI-8132
Project: Apache NiFi
Issue Type: Improvement
Components: Core Framework
Affects Versions: 1.12.1
Reporter: David Handermann
Assignee: David Handermann
[RFC 1321|https://tools.ietf.org/html/rfc1321] was published in 1992 and
described the MD5 message-digest algorithm. Multiple researchers have found
[security issues|https://en.wikipedia.org/wiki/MD5#Security] in the MD5
algorithm. The Federal Information Processing Standard 140-2 does not allow MD5
to be used.
Several NiFi framework classes use the MD5 algorithm for determining whether
file contents have changed. Although these uses do not relate directly to
encryption operations, use of the MD5 algorithm should be replaced with a
modern algorithm that is not subject to the same security issues.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)