Summary: | Secure downloads with PGP key and abolish SHA-1 | ||
---|---|---|---|
Product: | Infrastructure | Reporter: | Michael Tremer <michael.tremer> |
Component: | Web Site | Assignee: | Peter Müller <peter.mueller> |
Status: | CLOSED FIXED | QA Contact: | Michael Tremer <michael.tremer> |
Severity: | Security | ||
Priority: | Will affect all users | CC: | gerard5609, markrijckenberg, peter.mueller |
Version: | unspecified | Keywords: | Security |
Hardware: | unspecified | ||
OS: | Unspecified | ||
See Also: | https://bugzilla.ipfire.org/show_bug.cgi?id=11660 |
Description
Michael Tremer
2017-05-11 17:05:50 UTC
* ping * ;-) - ping - (again) If there is something I can do for solving this, let me know. sha1-diediedie :-) (In reply to Peter Müller from comment #2) > - ping - (again) > > If there is something I can do for solving this, let me know. > > sha1-diediedie :-) Yes, you could implement all of this :) Okay. If any questions arise, I will let you know. Seems like I do not have access to the webserver. Could you please show me which is the correct machine and grant access to it? Thanks. What do you need access to the web server for? (In reply to Michael Tremer from comment #6) > What do you need access to the web server for? Well, I guess the installation media checksums are living on some webserver (downloads.ipfire.org) ... Forget about my last comment. Just found the webapp file... :-\ https://git.ipfire.org/?p=ipfire.org.git;a=commit;h=752c8888e6038fec2f8b3fc1b97deb8b91a4dbce implements SHA256 checksums on website if available. (Thanks, Michael.) Hi, Thank you for implementing the SHA256 checksums on your website. I found them here: https://www.ipfire.org/download/ipfire-2.21-core125 Regards, Mark Rijckenberg Hey, thanks for being quicker than me. I added those to the database yesterday with the release. However, this isn't the end of the story for me. I still want a proper signature on the images instead of a cryptographically secure checksum. The purpose of the checksum is still being a checksum and nothing else :) *** Bug 12180 has been marked as a duplicate of this bug. *** Note that most distros are not signing the images themselves (too big), they are signing the hashes instead (see my bug 12180 for links showing that) |