Re: Strawberry Perl 5.24.2.1 released

[email protected] (Guitar Hero) Fri, 11 Aug 2017 01:15:20 -0400
Newsgroups perl.win32.vanilla
Message-ID <CAAf1vSwN2b91pYwqv5cx2PBh2K53YLQd=6Ly8_ESjuVwRd54Dg@mail.gmail.com>
--001a114b310249fcef0556736603
Content-Type: text/plain; charset="UTF-8"

I was wondering can I get an answer on this

On Sat, Jul 22, 2017 at 2:25 AM, Guitar Hero <[email protected]>
wrote:

> On Thu, Jul 20, 2017 at 6:00 PM, kmx <[email protected]> wrote:
>
>> Strawberry Perl 5.24.2.1 is available at http://strawberryperl.com
>>
>
>
> How come you don't sign the installer? I understand from 2 years ago if
> you can't use the Microsoft way but can't you use a gpg sig or something
> like that? Also the installers are not available via HTTPS. I don't want to
> be subject to a MITM attack when I download the installer and also I want
> to be sure it's actually from you. The integrity of these files is very
> important for me they are going to be installed on some important systems.
>
> These are the hashes I have, they match what is on the website. Can you
> please confirm if they are correct:
> e59ac8f708a621a52857cfc7477cdef19fe1aae9 *strawberry-perl-5.24.2.1-
> 32bit.msi
> e335e59ec61d3b13de392a43dc6fa3db88b56fec *strawberry-perl-5.24.2.1-
> 64bit.msi
>
>
>

--001a114b310249fcef0556736603
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I was wondering can I get an answer on this<br><div><div c=
lass=3D"gmail_extra"><br><div class=3D"gmail_quote">On Sat, Jul 22, 2017 at=
 2:25 AM, Guitar Hero <span dir=3D"ltr">&lt;<a href=3D"mailto:guitarhero683=
@gmail.com" target=3D"_blank">[email protected]</a>&gt;</span> wrote:=
<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-lef=
t:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_ext=
ra"><div class=3D"gmail_quote"><span class=3D"">On Thu, Jul 20, 2017 at 6:0=
0 PM, kmx <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_=
blank">[email protected]</a>&gt;</span> wrote:<br><blockquote style=3D"margin:0p=
x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" cl=
ass=3D"gmail_quote">Strawberry Perl 5.24.2.1 is available at <a rel=3D"nore=
ferrer" href=3D"http://strawberryperl.com" target=3D"_blank">http://strawbe=
rryperl.com</a><br></blockquote><div><br><br></div></span><div>How come you=
 don&#39;t sign the installer? I understand from 2 years ago if you can&#39=
;t use the Microsoft way but can&#39;t you use a gpg sig or something like =
that? Also the installers are not available via HTTPS. I don&#39;t want to =
be subject to a MITM attack when I download the installer and also I want t=
o be sure it&#39;s actually from you. The integrity of these files is very =
important for me they are going to be installed on some important systems.<=
br><br></div><div>These are the hashes I have, they match what is on the we=
bsite. Can you please confirm if they are correct:<br>e59ac8f708a621a52857c=
fc7477cde<wbr>f19fe1aae9 *strawberry-perl-5.24.2.1-<wbr>32bit.msi<br>e335e5=
9ec61d3b13de392a43dc6fa3<wbr>db88b56fec *strawberry-perl-5.24.2.1-<wbr>64bi=
t.msi<br><br></div></div><br></div></div>
</blockquote></div><br></div></div></div>

--001a114b310249fcef0556736603--