Using sha512 checksum for default in CD/verify page

Stéphane Blondon <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <[email protected]>
Hello,

on the page https://www.debian.org/CD/verify.en.html, the explanation is
more based on MD5 than on better checksum algorithms. I think it would
be better to talk about SHA512 for default example and MD5 as fallback only.

I made a patch for that (see attachment).

I removed the reference for SHA-1 because there are theoretical
collisions and I remember there is a removal of the use inside Debian
for signatures (but I don't remember exactly if it's for the iso
signatures.)

- Do you see improvements?
- Should I re-add SHA-1 ? With MD5, to group them in weak algorithms?

If it's ok, I will commit the patch in few days.


Regards
-- 
Stéphane
verify.diff (text/x-patch, 1.5 KB)
Index: english/CD/verify.wml
===================================================================
RCS file: /cvs/webwml/webwml/english/CD/verify.wml,v
retrieving revision 1.3
diff -u -w -r1.3 verify.wml
--- english/CD/verify.wml	1 Nov 2015 15:56:22 -0000	1.3
+++ english/CD/verify.wml	25 Sep 2016 14:36:39 -0000
@@ -15,18 +15,18 @@
 <p>
 To validate the contents of a CD image, just be sure to use the
 appropriate checksum tool.
-For older archived CD releases, only MD5 checksums were generated in
-the <code>MD5SUMS</code> files; you should use the tool
-<code>md5sum</code> to work with these.
-For newer releases, newer and cryptographically stronger checksum
-algorithms (SHA1, SHA256 and SHA512) are used, and there are equivalent
-tools available to work with these.
+For recent releases, cryptographically strong checksum
+algorithms (SHA256 and SHA512) are used; you should use the tools
+<code>sha256sum</code> or <code>sha512sum</code> to work with these.
+For older archived CD releases, if only MD5 checksums were generated in
+the <code>MD5SUMS</code> files, you should use the tool
+<code>md5sum</code>.
 </p>
 
 <p>
 To ensure that the checksums files themselves are correct, use GnuPG to
 verify them against the accompanying signature files (e.g.
-<code>MD5SSUMS.sign</code>).
+<code>SHA512SUMS.sign</code>).
 The keys used for these signatures are all in the <a
 href="http://keyring.debian.org">Debian GPG keyring</a> and the best
 way to check them is to use that keyring to validate via the web of
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJX5+QGAAoJEKK5G8bNTr3c0a0P/jmpMmXFXg2/oy/IfV8d4djt
IUlR9RlkvR7q4pcj6ogU3qOAHjDafDkma0f9W4h+p4Oi1ObVSt9QFhOCTGwIuVkG
YDpKdvQYOd34OSQjMHj4sG6uNxRU5eusC8z68acyNNL528hvBkW+kmLKOsNvd1Yl
bijplTU+JtLL1WQ311G42myxDVcsdEvKUdKa2ukDsgeNuUSFlRgdfgfIO+st4ZuM
usfmPjMUjrtxVVYt8CQwktohREu3OvL64kStmzj/BCNegn8WhXuaRGQWKCCjrpM1
nqic6hi4ZvnW+LAfJeakg9O11VCpvG1r2bQNCmMUU5n5nYmr9tLXbourRKP7SlUB
+fLwkjJvu6LrrwPXyza72rb/KHtcGlz2pgdlG98RyRMr4ot3NVc65tt0sywr19uX
q7ZzoP9x8pdiyA0+K5V+SSZXxEw8y0pBDxXNV9PqA4CaXQQIWpmwD9j1rXI6Cywc
VOYwDEDtBHSzmBMxMveLkBKnGnuzfssPPeiYdnn2W0hHSAwrjQqIpdsP/JGadDSm
n9KeKjBOjY+Dc0T0bJi/UvjBBHeXsS+KNCdsHvos6Dio9aG2bqZbppRv2bOoj6xA
ai7t72m323Llz4JuU5cakdZsfbxPK1MjNATPh4LAcHqWochVF7wtZxz0oK7f+FwQ
SoHnsvdnAU/hmSpDmZUx
=votq
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.