Return-Path: X-Original-To: apmail-incubator-ooo-users-archive@minotaur.apache.org Delivered-To: apmail-incubator-ooo-users-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 76DA5921E for ; Thu, 14 Jun 2012 14:24:29 +0000 (UTC) Received: (qmail 89613 invoked by uid 500); 14 Jun 2012 14:24:29 -0000 Delivered-To: apmail-incubator-ooo-users-archive@incubator.apache.org Received: (qmail 89572 invoked by uid 500); 14 Jun 2012 14:24:29 -0000 Mailing-List: contact ooo-users-help@incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: ooo-users@incubator.apache.org Delivered-To: mailing list ooo-users@incubator.apache.org Received: (qmail 89551 invoked by uid 99); 14 Jun 2012 14:24:29 -0000 Received: from minotaur.apache.org (HELO minotaur.apache.org) (140.211.11.9) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 14 Jun 2012 14:24:29 +0000 Received: from localhost (HELO mail-vc0-f175.google.com) (127.0.0.1) (smtp-auth username robweir, mechanism plain) by minotaur.apache.org (qpsmtpd/0.29) with ESMTP; Thu, 14 Jun 2012 14:24:27 +0000 Received: by vcbfl15 with SMTP id fl15so1048618vcb.6 for ; Thu, 14 Jun 2012 07:24:26 -0700 (PDT) MIME-Version: 1.0 Received: by 10.52.91.195 with SMTP id cg3mr965115vdb.96.1339683866379; Thu, 14 Jun 2012 07:24:26 -0700 (PDT) Received: by 10.220.190.13 with HTTP; Thu, 14 Jun 2012 07:24:26 -0700 (PDT) In-Reply-To: References: Date: Thu, 14 Jun 2012 10:24:26 -0400 Message-ID: Subject: Re: Wrong checksum and unknown publisher From: Rob Weir To: ooo-users@incubator.apache.org, eroenvvb@gmail.com Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Thu, Jun 14, 2012 at 8:42 AM, J B wrote: > Dear technicians, > HI JB, > I suspect you have some kind of trojan problem. > > *First clue* > I deinstalled your software and I was directed to your survey webpage. Bu= t > the page was unavailable. > It was not necessary to uninstall the previous version of OOo before installing Apache OpenOffice 3.4, but if you did that would be the expected behavior. When the project moved to Apache we turned off the survey collection that Sun had until we could figure out whether we wanted it and if we did how to handle the data protection and data privacy aspects of this. So the error was expected > > *Second clue* > When reinstalling, Windows said that the publisher was unknown. Normally = it > says your organisation. > Prior versions were built and digitally signed by Sun. AOO 3.4 did not have an Authenticode digital signature. Instead Apache projects provide a detached PGP/GPG digital signature. However, these signatures are more understood in the Linux admin world, and are not recognized by Microsoft Windows. Thus the warning you see with AOO 3.4. We're looking into providing an Authenticode signature for future releases to avoid this issue. > Then I did a checksum and it did not match. > > ( Should be: =C2=A0a919dc6c480feee7748a63d5d4d03f85 > =C2=A0Apache_OpenOffice_incubating_3.4.0_Win_x86_langpack_en-US.exe > =C2=A0But is: =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 089966F62006BA94E540A9BB= B3E6056A > C:\Users\Koblenz\Downloads\Apache_OpenOffice_incubating_3.4.0_Win_x86_ins= tall_en-US.exe) > Where are you finding the "should be" checksums? The checksum for the en_US version is here: http://www.apache.org/dist/incubator/ooo/files/stable/3.4.0/Apache_OpenOffi= ce_incubating_3.4.0_Win_x86_install_en-US.exe.md5 I just downloaded the en_US version of AOO 3.4 and the md5 checksums matche= d. > Could be that you have two different files. =C2=A0But it is suspicious. > (I did the same check with the Dutch files) > > Do you have a download link that I can totally trust? > And - very important - should the publisher be known? > The checksum files are on our most trusted server. So those come directly from Apache, not via an operator of a mirror. There is always the theoretical possibility of a rogue mirror operator, or corruption caused during or after your download. But if you verify against the checksums hosted on apache.org, you protect against that. -Rob > Regards, > > Jeroen > Holland --------------------------------------------------------------------- To unsubscribe, e-mail: ooo-users-unsubscribe@incubator.apache.org For additional commands, e-mail: ooo-users-help@incubator.apache.org