Re: Strawberry Perl 5.24.2.1 released
[email protected] (Guitar Hero) Sat, 22 Jul 2017 02:25:01 -0400
| Newsgroups | perl.win32.vanilla |
|---|---|
| Message-ID | <CAAf1vSyU_wKfZaQJ8uPYk26nSgie+evmmyS4o9nOVCBa_e+Bjw@mail.gmail.com> |
--001a1141716caa90010554e20aba Content-Type: text/plain; charset="UTF-8" On Thu, Jul 20, 2017 at 6:00 PM, kmx <[email protected]> wrote: > Strawberry Perl 5.24.2.1 is available at http://strawberryperl.com > How come you don't sign the installer? I understand from 2 years ago if you can't use the Microsoft way but can't you use a gpg sig or something like that? Also the installers are not available via HTTPS. I don't want to be subject to a MITM attack when I download the installer and also I want to be sure it's actually from you. The integrity of these files is very important for me they are going to be installed on some important systems. These are the hashes I have, they match what is on the website. Can you please confirm if they are correct: e59ac8f708a621a52857cfc7477cdef19fe1aae9 *strawberry-perl-5.24.2.1-32bit.msi e335e59ec61d3b13de392a43dc6fa3db88b56fec *strawberry-perl-5.24.2.1-64bit.msi --001a1141716caa90010554e20aba Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">On T= hu, Jul 20, 2017 at 6:00 PM, kmx <span dir=3D"ltr"><<a target=3D"_blank"= href=3D"mailto:[email protected]">[email protected]</a>></span> wrote:<br><blockq= uote style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,20= 4);padding-left:1ex" class=3D"gmail_quote">Strawberry Perl 5.24.2.1 is avai= lable at <a target=3D"_blank" rel=3D"noreferrer" href=3D"http://strawberryp= erl.com">http://strawberryperl.com</a><br></blockquote><div><br><br></div><= div>How come you don't sign the installer? I understand from 2 years ag= o if you can't use the Microsoft way but can't you use a gpg sig or= something like that? Also the installers are not available via HTTPS. I do= n't want to be subject to a MITM attack when I download the installer a= nd also I want to be sure it's actually from you. The integrity of thes= e files is very important for me they are going to be installed on some imp= ortant systems.<br><br></div><div>These are the hashes I have, they match w= hat is on the website. Can you please confirm if they are correct:<br>e59ac= 8f708a621a52857cfc7477cdef19fe1aae9 *strawberry-perl-5.24.2.1-32bit.msi<br>= e335e59ec61d3b13de392a43dc6fa3db88b56fec *strawberry-perl-5.24.2.1-64bit.ms= i<br><br></div></div><br></div></div> --001a1141716caa90010554e20aba--