Re: Warning for PGP Users!
Each new version of PGP should contain a file with MD5 hashes of each of the source files, and the whole file with MD5 hash should be clearsigned by one of the developers (Branko, I think).
I checked the .tar file at soda.berkeley.edu and the sources have several mismatching MD5s. Is anyone looking at this? - Carl
I checked the .tar file at soda.berkeley.edu and the sources have several mismatching MD5s. Is anyone looking at this?
Yes, the PGP 2.3A distribution has incorrect MD5 values in contrib/md5sum/pgp23.md5. I think that they were not updated to acount for the changes between versions 2.3 and 2.3A. Nevertheless, the file pgp23sigA.asc (which is distributed separately from the .tar.Z and .zip files) contains good detached signatures from Colin Plumb, covering the various .zip and .tar.Z files for PGP 2.3A. --apb (Alan Barrett)
participants (2)
-
Alan Barrett -
Carl Ellison