httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Guenter Knauf <fua...@apache.org>
Subject Re: add chkdigest.pl to download.xml
Date Sun, 15 May 2011 22:01:43 GMT
Am 15.05.2011 23:26, schrieb Graham Leggett:
> On 15 May 2011, at 10:26 PM, Guenter Knauf wrote:
>
>> I'd like to add:
>> http://people.apache.org/~fuankg/chkdigest/
>> as a cross-platform tool for verifying checksums to the last section
>> on download.xml - any thoughts?
>
> The simplest way to check the checksum is to, using the operating system
> of choice, copy the output from md5sum (or local tool of choice) on the
> binary downloaded, and paste this into the "find" functionality of the
> web browser of choice while displaying the md5 checksum of the file as
> published by us. If the md5 hashes match, the "find" will be successful.
we discussed this already here around mid of 2009 - no reason to point 
it out again - I'm aware of almost every ugly method to verify 
checksums; see also my post here which lists whats all possible and why 
I choosed to write my own script (in addition to patching coreutils and 
openssl):
http://www.gknw.net/phpbb/viewtopic.php?t=570

> This mechanism relies on software already present on and trusted by the
> end user's computer (within reason), and is simple to understand without
> introducing trust on a new tool.
my suggestion just derived from the fact that we actually already list 
some checksum tools at the bottom of the D/L page for Windows (where no 
trusted tool ships with the OS).

Gün.



Mime
View raw message