MD5 is not the hash you want to use. It has been clearly demonstrated over the last couple of years that collisions can be forced.
With respect to encryption, is the JSP code doing the encryption or are you wanting to do it inside SQL Server?
K. Brian Kelley
@kbriankelley