Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-30 Thread Brian Rosmaita
On Fri, Sep 29, 2017 at 1:38 PM, Jeremy Stanley wrote: > On 2017-09-29 12:31:21 -0400 (-0400), Jay Pipes wrote: > [...] >> Can someone please inform me how changing the checksum algorithm >> for this operation to SHA-1 or something else would improve the >> security of this

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Luke Hinds
On Fri, Sep 29, 2017 at 5:31 PM, Jay Pipes wrote: > On 09/29/2017 06:19 AM, Luke Hinds wrote: > >> On Thu, Sep 28, 2017 at 8:38 PM, McClymont Jr, Scott < >> scott.mcclym...@verizonwireless.com > nwireless.com>> wrote: >> >> Hey All, >> >>

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Jeremy Stanley
On 2017-09-29 12:31:21 -0400 (-0400), Jay Pipes wrote: [...] > Can someone please inform me how changing the checksum algorithm > for this operation to SHA-1 or something else would improve the > security of this operation? [...] The current known flaws in MD5 pretty much boil down to this one

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Jay Pipes
On 09/29/2017 06:19 AM, Luke Hinds wrote: On Thu, Sep 28, 2017 at 8:38 PM, McClymont Jr, Scott > wrote: Hey All, I've got a spec up for a change I want to implement in Glance for Queens to enhance

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Adam Heczko
Thanks Scott, makes sense. On Fri, Sep 29, 2017 at 12:19 PM, Luke Hinds wrote: > > > On Thu, Sep 28, 2017 at 8:38 PM, McClymont Jr, Scott verizonwireless.com> wrote: > >> Hey All, >> >> I've got a spec up for a change I want to implement in Glance for

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Luke Hinds
On Thu, Sep 28, 2017 at 8:38 PM, McClymont Jr, Scott < scott.mcclym...@verizonwireless.com> wrote: > Hey All, > > I've got a spec up for a change I want to implement in Glance for Queens > to enhance the current checksum (md5) functionality with a stronger hash > algorithm. I'm going to do this

[openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-28 Thread McClymont Jr, Scott
Hey All, I've got a spec up for a change I want to implement in Glance for Queens to enhance the current checksum (md5) functionality with a stronger hash algorithm. I'm going to do this in such a way that it is easily altered in the future for new algorithms as they are released. I'd appreciate