PDA

View Full Version : GPG signed md5sum



FunkyRes
05-05-2004, 06:14 PM
I would like it if the knoppix team would provide a gpg signed md5sum file for the knoppix iso's.

I downloaded knoppix 3.4 from a torrent last night.
This morning I looked at the md5sum - and it is different than the md5sum I got from an official knoppix mirror.

With Fedora, the gpg sign the md5sum file, and the torrents include the signed md5sum file - so that I can verify the md5sum is good, and then verify that the iso is good.

I can't trust an md5sum from an unknown torrent (and the one I used did not provide one anyway) unless it is properly signed by the knoppix team, and it would make it easier to properly verify a torrent download if the torrent had a signed md5sum with it.

zentu
05-06-2004, 01:43 AM
Ummm... isn't that what the .asc file is (hint open it and look). It has been included with the torrents since he started them, and if I remember correctly, then it has been on the FTP servers since i started in late 1.x.

it is (from the 3.4 us file


----BEGIN PGP SIGNED MESSAGE-----

49a62cdac7a3afcee0d2d47ea17daa6f *KNOPPIX_V3.4-2004-05-04-EN.iso
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iQCVAwUBQJa5kTLvxgG6jwONAQGLtQQAmbMJkqiTW1gXFqaQlo op2UI2Vg5K/p2p
liWF0ELC9VPl4hQtD9Mt7NFHxlQ6rkZXMPAhncc3raEgJk8dej EYbtKWUJ9oSvId
485nu8+3qAwHO/iSvQpjA4grM7gEW2ltB21kIs9DvBc2jbH3WQ7kUy8R1iEWAdDe
S6yru/BntX8=
=DNzr
-----END PGP SIGNATURE-----