Hello everyone,
We are currently using Moodle with 2.7 and our security vendor said the SHA1 will be retired soon, and it seems Moodle is using SHA1/MD5 for encryption
They have below vulnerability comments:
Vulnerability: Use of Broken or Risky Cryptographic Algorithm
Impact: The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the disclosure of sensitive information.
Recommendation: Use SHA-2 instead of SHA-1
Sorry, I am new to this forum and I tried to search around Moodle docs and it seems there is no information about this. Would someone please provide more information if Moodle is safeguard of SHA1 issue?
What I got is something related is the Moodle's Password salting (https://docs.moodle.org/23/en/Password_salting)
Many thanks,
Tanky