Re: API for SHA-256 fingerprints

Jeremy Stanley <[email protected]>
Newsgroups gmane.comp.python.distutils.devel
Message-ID <[email protected]>
On 2019-02-12 12:42:27 -0500 (-0500), Wes Turner wrote:
[...]
> - cryptographically sign the SHA-256 checksums with a key and retrieve the
> corresponding key over a different channel
[...]

If you're going to use asymmetric cryptography with PKI to sign
something, you might as well just directly sign (a hash of) the
package file rather than merely signing (a hash of) its checksum.
Either way you're relying on the strength of your signing
implementation, so also having to rely on the strength of the
checksum is just added potential weakness and complexity.
-- 
Jeremy Stanley

--
Distutils-SIG mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/distutils-sig.python.org/
Message archived at https://mail.python.org/archives/list/[email protected]/message/22DUNOXZSRCBQBT3CLTRJHICB5LKKSSI/
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAlxjIlxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WClm8hAAtK4KKOnDjOKui+okJn0H9dg/SijYcma/F2OitUrcWkzqcNJpkjxy3gw4
7uu2QRqHQNfxs4Jm6DTZcJn2U2tj9kbcENkAr0X0wp75CZ9CKnl4RU3Zvd0159KD
wjKawzMeKTOPXuOIj675IAMgAFNf3LPUh7TYiqjVEwabc27l3P9htCpxpbJv629g
ZZ3vl7o1mGYyC6FMwy1w2Z2gxKc0pe+4FEFyWHVbVYjRGWcOJOMVpg3KMVPKh5D3
HXIYKwXrVVSFBIioUZbOLdTSHCLTMhyxS0a+LL9PpRdjbCq0p9oO2XvksvJ+vZM8
i9iwIRYoff6qy9m7FPDLa+lNR9DJodc6A9/r5cQ2avcfpfkQD7kPGSYUnD11Ie+X
mM4MYo8embr8eOYG2u/4tfFpEb6bgDWVidptAOhjbGiGkMRiivnDdgHIlOKr1HVd
lw007j4J5kdpFv04F7H9WT9ARa4Ib3k9KbjycSDpevyQmiUOXOXoYoWa88QMGR8D
3BlisIPR4jP3U95I6MktV2jX570t81zFeKNVYSJIhJXcr6kBBPrdSLlBBKQccWtF
wFAZfXWPCGf/8KUARZYS+cFOXRQDRHzagKA/+oDlVJnUtOjJg0jNeWvuboyTv1T3
86ZFhQPxiiAGLT+l7IZE2QGDOxHE5e2VujivBoGhv14KmA90eOQ=
=WkDn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.