Re: PGP signing releases - Mailing list pgsql-hackers

From Greg Copeland
Subject Re: PGP signing releases
Date
Msg-id 1044296653.2788.55.camel@mouse.copelandconsulting.net
Whole thread Raw
In response to Re: PGP signing releases  ("Marc G. Fournier" <scrappy@hub.org>)
Responses Re: PGP signing releases  (Kurt Roeckx <Q@ping.be>)
List pgsql-hackers
On Sun, 2003-02-02 at 20:23, Marc G. Fournier wrote:

> right, that is why we started to provide md5 checksums ...

md5 checksums only validate that the intended package (trojaned or
legit) has been properly received.  They offer nothing from a security
perspective unless the checksums have been signed with a key which can
be readily validated from multiple independent sources.

Regards,

-- 
Greg Copeland <greg@copelandconsulting.net>
Copeland Computer Consulting



pgsql-hackers by date:

Previous
From: Katie Ward
Date:
Subject: Re: Win32 Technical Questions
Next
From: Rod Taylor
Date:
Subject: Re: Win32 Powerfail testing - results