Re: Strawberry Perl 5.24.2.1 released
[email protected] (Guitar Hero) Fri, 11 Aug 2017 01:15:20 -0400
| Newsgroups | perl.win32.vanilla |
|---|---|
| Message-ID | <CAAf1vSwN2b91pYwqv5cx2PBh2K53YLQd=6Ly8_ESjuVwRd54Dg@mail.gmail.com> |
--001a114b310249fcef0556736603 Content-Type: text/plain; charset="UTF-8" I was wondering can I get an answer on this On Sat, Jul 22, 2017 at 2:25 AM, Guitar Hero <[email protected]> wrote: > On Thu, Jul 20, 2017 at 6:00 PM, kmx <[email protected]> wrote: > >> Strawberry Perl 5.24.2.1 is available at http://strawberryperl.com >> > > > How come you don't sign the installer? I understand from 2 years ago if > you can't use the Microsoft way but can't you use a gpg sig or something > like that? Also the installers are not available via HTTPS. I don't want to > be subject to a MITM attack when I download the installer and also I want > to be sure it's actually from you. The integrity of these files is very > important for me they are going to be installed on some important systems. > > These are the hashes I have, they match what is on the website. Can you > please confirm if they are correct: > e59ac8f708a621a52857cfc7477cdef19fe1aae9 *strawberry-perl-5.24.2.1- > 32bit.msi > e335e59ec61d3b13de392a43dc6fa3db88b56fec *strawberry-perl-5.24.2.1- > 64bit.msi > > > --001a114b310249fcef0556736603 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I was wondering can I get an answer on this<br><div><div c= lass=3D"gmail_extra"><br><div class=3D"gmail_quote">On Sat, Jul 22, 2017 at= 2:25 AM, Guitar Hero <span dir=3D"ltr"><<a href=3D"mailto:guitarhero683= @gmail.com" target=3D"_blank">[email protected]</a>></span> wrote:= <br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-lef= t:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_ext= ra"><div class=3D"gmail_quote"><span class=3D"">On Thu, Jul 20, 2017 at 6:0= 0 PM, kmx <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D"_= blank">[email protected]</a>></span> wrote:<br><blockquote style=3D"margin:0p= x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" cl= ass=3D"gmail_quote">Strawberry Perl 5.24.2.1 is available at <a rel=3D"nore= ferrer" href=3D"http://strawberryperl.com" target=3D"_blank">http://strawbe= rryperl.com</a><br></blockquote><div><br><br></div></span><div>How come you= don't sign the installer? I understand from 2 years ago if you can'= ;t use the Microsoft way but can't you use a gpg sig or something like = that? Also the installers are not available via HTTPS. I don't want to = be subject to a MITM attack when I download the installer and also I want t= o be sure it's actually from you. The integrity of these files is very = important for me they are going to be installed on some important systems.<= br><br></div><div>These are the hashes I have, they match what is on the we= bsite. Can you please confirm if they are correct:<br>e59ac8f708a621a52857c= fc7477cde<wbr>f19fe1aae9 *strawberry-perl-5.24.2.1-<wbr>32bit.msi<br>e335e5= 9ec61d3b13de392a43dc6fa3<wbr>db88b56fec *strawberry-perl-5.24.2.1-<wbr>64bi= t.msi<br><br></div></div><br></div></div> </blockquote></div><br></div></div></div> --001a114b310249fcef0556736603--