There should be an option for users to switch the fingerprint algorithm from MD5 to another algorithm (specifically SHA256). Other applications like Chef have already switched from using MD5 to SHA256 (See CHEF-27).

          [JENKINS-25808] Set SHA256 as a fingerprint algorithm

          Steven Christou created issue -
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 159788 ] New: JNJira + In-Review [ 180127 ]

          Matt Wilson added a comment -

          SHA256 would be nice. Ideally it would be great if we could get 3 listed. Sort of how Artifactory does it.

          SHA-1
          SHA-256
          MD5

          Matt Wilson added a comment - SHA256 would be nice. Ideally it would be great if we could get 3 listed. Sort of how Artifactory does it. SHA-1 SHA-256 MD5
          Jesse Glick made changes -
          Labels New: fingerprints security
          Jesse Glick made changes -
          Issue Type Original: New Feature [ 2 ] New: Bug [ 1 ]
          Jesse Glick made changes -
          Link New: This issue relates to SECURITY-469 [ SECURITY-469 ]

          Ryan Stark added a comment -

          MD5 and SHA1 are both broken, SHA256 is the new standard.

          Ryan Stark added a comment - MD5 and SHA1 are both broken, SHA256 is the new standard.
          James Dumay made changes -
          Remote Link New: This issue links to "CloudBees Internal OSS-2099 (Web Link)" [ 18421 ]

          Are there any plans to make this change?

          Daniel Becroft added a comment - Are there any plans to make this change?
          Oleg Nenashev made changes -
          Labels Original: fingerprints security New: fingerprints security technical-debt

            Unassigned Unassigned
            schristou Steven Christou
            Votes:
            8 Vote for this issue
            Watchers:
            12 Start watching this issue

              Created:
              Updated: