 |
 |
 |
 |
| Installation and Live Media Help with Installation & Live Media (Live CD, USB, DVD) problems. |

16th April 2010, 01:17 AM
|
|
Registered User
|
|
Join Date: Jan 2010
Posts: 5,024

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
I can tell if I see them side by side. But if I just saw
086fd570518ac58d3966c43c1b6d146e38919d8d
or even the shorter
ca49964739f84848ca78fc03662272fb
I really wouldn't know. I'm still impressed.
|

16th April 2010, 02:01 AM
|
|
Registered User
|
|
Join Date: Jun 2006
Posts: 7,551

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
I have to admit that I cheated (sorta) when the change from MD5 to SHA-1 hashes happened with Fedora Core 4... In those days, the checksum files had the names MD5SUM and SHA1SUM. Only the most inattentive person would have missed or been confused by those. The change to SHA-256 hashes with Fedora 11 was accompanied by the change to those checksum filenames which no longer gave the clue. But the difference in the lengths of SHA-1 and SHA-256 is too great to miss.
P.S.: That "SHA1" thing in the text of the checksum files has always been there, even in the old MD5SUM checksum files all the way back to Fedora Core 1. So it was understandable for it to still be in the new checksum files starting with Fedora 11. But that's when the wheels fell off, and this subject became a popular topic for discussion.
|

16th April 2010, 02:33 AM
|
|
Registered User
|
|
Join Date: Jan 2010
Posts: 5,024

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
Maybe more people started checking? Seems to me that prior to F11 or so, they might have been in their own directory, and labeled as whatever they were. For example, CentOS, which probably follows RH, has a separate directory marked SHA1 sums, or possibly even md5sums, or something.
Again, I think the difference is only too great to miss for some talented folks, or folks who work with the sums frequently. Shucks, even the distrowatch folks made the mistake, and one imagines that they frequently work with the sums. I think that we less talented folks only look at them when we download something, and don't pay that much attention. Or maybe I'm just I'm just either dumb, or more charitably, somewhat oblivious. I feel I have to surrender my elite card. :-(
|

18th April 2010, 06:30 AM
|
 |
Registered User
|
|
Join Date: Sep 2009
Location: Michigan USA
Posts: 128

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
Quote:
Originally Posted by RahulSundaram
There is no reliable SHA256 checksum binary for Windows that we can point users to.
|
I use HashCalc in Win - http://www.slavasoft.com/?source=HashCalc.exe
I admit I haven't burned it in with constant hashing for 3 days straight, but what's 'unreliable' about it?
|

18th April 2010, 06:49 AM
|
|
Registered User
|
|
Join Date: May 2005
Posts: 3,579

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
Hi,
For one thing, unless we have the source to it, we can't verify whether the hash it generates is accurate in all instances. Primary recommendation would have to be something we can verify the accuracy of, especially since this is security sensitive. This problem has now been solved by using MingGW to cross compile the Linux source.
__________________
Rahul
http://fedoraproject.org/wiki/RahulSundaram
|

18th April 2010, 06:51 AM
|
 |
Banned (for/from) behaving just like everybody else!
|
|
Join Date: Jul 2007
Location: Beijing, China
Posts: 1,307

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
The SHA1 thing is the hashing algorithm used to generate the PGP signature (cf http://www.ietf.org/rfc/rfc4880.txt). It has nothing to do with the content of the message signed, which contains SHA256 checksum info for the install image files.
And yep, more people are getting the idea of checking the media, but not all of them groks PGP at the same time
__________________
I believe in nerditarianism. I read FedoraForum for the Fedora-related posts.
Last edited by aleph; 18th April 2010 at 07:12 AM.
Reason: Update RFC number
|

18th April 2010, 07:39 AM
|
 |
Registered User
|
|
Join Date: Sep 2009
Location: Michigan USA
Posts: 128

|
|
|
Re: Please someone update the Sha1 Checksum info in the Fedora verify pages
p.s.
FreeDownloadManager (freedownloadmanager.org) can perform an integrity check when it's done, not unlike your favorite torrent app (in fact, FDM does torrents too), if you paste in the value that is supposed to match anytime before the download finishes.
In the attached I showed the different hashes it can check instead of the choices of what to do if it doesn't match... the latter are Ask (shown), Restart Download, or Do Nothing.
For people using something like that, it might turn out to be important for them to know if it's really sha1 or sha256, e.g. if their internet service is tiered and they must pay extra if they go over a certain GB level... otherwise if they set it to Restart if the checksum didn't match and went to bed it might download a hundred times before they woke up.
Sure... NOW it doesn't append to my previous post in this thread.
Last edited by Darr247; 18th April 2010 at 07:41 AM.
Reason: 'cause I felt like it
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Current GMT-time: 12:23 (Thursday, 20-06-2013)
|
|
 |
 |
 |
 |
|
|