Upgrade the embedded checksum from MD5 to SHA256?
Roland Clobus <[email protected]>
| Newsgroups | gmane.linux.debian.devel.cd |
|---|---|
| Message-ID | <[email protected]> |
Hello list, In the Debian-installer main menu the entry 'Check the integrity of installation media' verifies whether the currently booted image is untampered (package=cdrom-checker). It reads the file 'md5sum.txt' and verifies all files listed there [1]. In live-build we provide sha256sum.txt since 2020-03-18, since MD5 checksums are known to be insecure. There are good instructions on the download pages [2] that help with verification of the downloaded ISO file using sha256 and sha512, but the verification on a booted medium uses only md5. Could/Should the checksum file be upgrade to use sha256 instead of md5? I could provide a MR if desired. The cost: 32 additional bytes per file. (With currently about 1200 files that would be 38KiB) With kind regards, Roland Clobus [1] https://sources.debian.org/src/cdrom-checker/1.65/main.c/#L115 [2] https://get.debian.org/images/weekly-live-builds/amd64/iso-hybrid/
OpenPGP_signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUFVLM5Bdj7GSJEb+YsV8aqYUlb0FAmdes3gACgkQYsV8aqYU lb3n4g/+PdsmAfqH/aS3VeIWrY9A10bS767Qr7+lZXOlw/pDXka6ApYDfp0PTl3Z jV26fG+cV3VcU2LmN8xbIUpvdU1jTc7F3Ho9zTrmos1krpj/dZD/R8X2IXU8v9Rw oczLjdx+AMIL4jH6L19h9N7czzXZqbPIMXe+mYSVCb0NNmZaP1vcVR+ZWQO8VHG/ p1oFRXwL1Kw4M9iYTeOaX8v5oVnhu1QmwhPpg92VZiP7pGx//61il8OuIv12/GEp xP8apvYY1+m52I6x2htt5elTiWqvuHNimVtrVsEv8nzAAybbGKVnbNnT9LNjQJWz 6/9s5v6raSHbE+5FSp5WNHpiZzIEjvoM66E4HHl+ygUr1Lvx31oFsy1sukCzjAst 0ALvJR0k7zytsc3EzXGeS44WsSbjNr6WkD/BhbgyoB7xUI0xXwYEp0+e4lBarG9n DDi3T5m/GdRspP0JcZe6YdGX6XqizThBeLVAvlINaJcdXLS9r80BvAsjb8p9VtHP 81chhG6qgIYmEEuRZhIrJsZb159IuqWgtS8rc2s+LXkF4aVP9vERCI99GQYV3Kke d+rBDGy9apMcdsZMBmSqZlxoZskepoSOe/yNoRbPpKiMO7T6+VkCx4QSpVjw2Nt8 qxM2TG9VWV+IjuUrNb7Y63tYxP6R3cY7baf4rJ2Mzqo2bbaWSaQ= =A88N -----END PGP SIGNATURE-----