Re: API for SHA-256 fingerprints
Jeremy Stanley <[email protected]>
| Newsgroups | gmane.comp.python.distutils.devel |
|---|---|
| Message-ID | <[email protected]> |
On 2019-02-12 12:42:27 -0500 (-0500), Wes Turner wrote: [...] > - cryptographically sign the SHA-256 checksums with a key and retrieve the > corresponding key over a different channel [...] If you're going to use asymmetric cryptography with PKI to sign something, you might as well just directly sign (a hash of) the package file rather than merely signing (a hash of) its checksum. Either way you're relying on the strength of your signing implementation, so also having to rely on the strength of the checksum is just added potential weakness and complexity. -- Jeremy Stanley -- Distutils-SIG mailing list -- [email protected] To unsubscribe send an email to [email protected] https://mail.python.org/mailman3/lists/distutils-sig.python.org/ Message archived at https://mail.python.org/archives/list/[email protected]/message/22DUNOXZSRCBQBT3CLTRJHICB5LKKSSI/
signature.asc
(application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAlxjIlxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3 QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ WClm8hAAtK4KKOnDjOKui+okJn0H9dg/SijYcma/F2OitUrcWkzqcNJpkjxy3gw4 7uu2QRqHQNfxs4Jm6DTZcJn2U2tj9kbcENkAr0X0wp75CZ9CKnl4RU3Zvd0159KD wjKawzMeKTOPXuOIj675IAMgAFNf3LPUh7TYiqjVEwabc27l3P9htCpxpbJv629g ZZ3vl7o1mGYyC6FMwy1w2Z2gxKc0pe+4FEFyWHVbVYjRGWcOJOMVpg3KMVPKh5D3 HXIYKwXrVVSFBIioUZbOLdTSHCLTMhyxS0a+LL9PpRdjbCq0p9oO2XvksvJ+vZM8 i9iwIRYoff6qy9m7FPDLa+lNR9DJodc6A9/r5cQ2avcfpfkQD7kPGSYUnD11Ie+X mM4MYo8embr8eOYG2u/4tfFpEb6bgDWVidptAOhjbGiGkMRiivnDdgHIlOKr1HVd lw007j4J5kdpFv04F7H9WT9ARa4Ib3k9KbjycSDpevyQmiUOXOXoYoWa88QMGR8D 3BlisIPR4jP3U95I6MktV2jX570t81zFeKNVYSJIhJXcr6kBBPrdSLlBBKQccWtF wFAZfXWPCGf/8KUARZYS+cFOXRQDRHzagKA/+oDlVJnUtOjJg0jNeWvuboyTv1T3 86ZFhQPxiiAGLT+l7IZE2QGDOxHE5e2VujivBoGhv14KmA90eOQ= =WkDn -----END PGP SIGNATURE-----