Re: [Maria-discuss] Is it possible to upgrade SHA-1 and MD5 algorithms in Mariadb-10.5?

2021-03-17 Thread Sergei Golubchik
Hi, Lukas! What do you mean by "upgrade SHA-1 and MD5 algorithms in MariaDB" ? Regards, Sergei VP of MariaDB Server Engineering and secur...@mariadb.org On Mar 17, Lukas Javorsky wrote: > Hi, > > In RHEL-9 we are deprecating, old SHA-1 and MD5 and that's why I want to > ask you if there is any

[Maria-discuss] Is it possible to upgrade SHA-1 and MD5 algorithms in Mariadb-10.5?

2021-03-17 Thread Lukas Javorsky
Hi, In RHEL-9 we are deprecating, old SHA-1 and MD5 and that's why I want to ask you if there is any chance that upstream is going to change it, or we should do it downstream. These algorithms are no longer considered as safe, so it may be a good thing to upgrade them. AFAIK mariadb uses these

Re: [Maria-discuss] Is it possible to upgrade SHA-1 and MD5 algorithms in Mariadb-10.5?

2021-03-17 Thread Eliezer Croitoru
Hey Sergei, I cannot speak in the name of Lukas but I assume that he is talking about the payload signature of RPM files. Technically speaking SHA1 and MD5 can collide but only to specific file sizes. It's not that simple to create an RPM in a size of 10+ MB which will provide the exact same