Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-8132

Replace Framework Uses of MD5 with Modern Algorithm

    XMLWordPrintableJSON

Details

    Description

      RFC 1321 was published in 1992 and described the MD5 message-digest algorithm. Multiple researchers have found security issues in the MD5 algorithm. The Federal Information Processing Standard 140-2 does not allow MD5 to be used.

      Several NiFi framework classes use the MD5 algorithm for determining whether file contents have changed. Although these uses do not relate directly to encryption operations, use of the MD5 algorithm should be replaced with a modern algorithm that is not subject to the same security issues.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 4h 20m
                  4h 20m