Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Checksums are not GPG signed. Instructions show how to GPG verify. #183

Open
xgpt opened this issue Jan 23, 2024 · 2 comments
Open

Checksums are not GPG signed. Instructions show how to GPG verify. #183

xgpt opened this issue Jan 23, 2024 · 2 comments

Comments

@xgpt
Copy link

xgpt commented Jan 23, 2024

https://get.opensuse.org/tumbleweed/ says:

Verify Your Download Before Use

Many applications can verify the checksum of a download. To verify your download can be important as it verifies you really have got the ISO file you wanted to download and not some broken version.

For each ISO, we offer a checksum file with the corresponding SHA256 sum.

For extra security, you can use sha256sum to verify who signed those .sha256 files.

It should be [AD48 5664 E901 B867 051A B15F 35A2 F86E 29B7 00A4](https://download.opensuse.org/tumbleweed/repo/oss/gpg-pubkey-29b700a4-62b07e22.asc)

For more help verifying your download please read [Checksums Help](https://en.opensuse.org/SDB:Download_help#Checksums)

Please consider removing the GPG verification instructions, or modifying the checksums available for download to indeed be GPG signed.

@tacerus
Copy link
Member

tacerus commented Jul 17, 2024

The checksum files are signed using a detached signature, can you elaborate what issue you are facing?

$ curl -sL https://download.opensuse.org/tumbleweed/iso/openSUSE-Tumbleweed-DVD-x86_64-Current.iso.sha256.asc|head -n2
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

@mdogg-11
Copy link

mdogg-11 commented Jul 17, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants