HIVE-17514 : Use SHA-256 for cookie signer to improve security (Tao Li reviewed by Thejas Nair)
Project: http://git-wip-us.apache.org/repos/asf/hive/repo Commit: http://git-wip-us.apache.org/repos/asf/hive/commit/b8f6ce08 Tree: http://git-wip-us.apache.org/repos/asf/hive/tree/b8f6ce08 Diff: http://git-wip-us.apache.org/repos/asf/hive/diff/b8f6ce08 Branch: refs/heads/hive-14535 Commit: b8f6ce085fdaec57d897c2793d3d5220f60acc33 Parents: 1706a6b Author: Thejas M Nair <the...@hortonworks.com> Authored: Fri Sep 15 15:57:36 2017 -0700 Committer: Thejas M Nair <the...@hortonworks.com> Committed: Fri Sep 15 15:57:36 2017 -0700 ---------------------------------------------------------------------- service/src/java/org/apache/hive/service/CookieSigner.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) ---------------------------------------------------------------------- http://git-wip-us.apache.org/repos/asf/hive/blob/b8f6ce08/service/src/java/org/apache/hive/service/CookieSigner.java ---------------------------------------------------------------------- diff --git a/service/src/java/org/apache/hive/service/CookieSigner.java b/service/src/java/org/apache/hive/service/CookieSigner.java index 046de7c..9c8bd56 100644 --- a/service/src/java/org/apache/hive/service/CookieSigner.java +++ b/service/src/java/org/apache/hive/service/CookieSigner.java @@ -32,7 +32,7 @@ import org.slf4j.LoggerFactory; */ public class CookieSigner { private static final String SIGNATURE = "&s="; - private static final String SHA_STRING = "SHA"; + private static final String SHA_STRING = "SHA-256"; private byte[] secretBytes; private static final Logger LOG = LoggerFactory.getLogger(CookieSigner.class);