X2Go Bug report logs - #54
Missing signatures for downloads

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: "glpk xypron" <xypron.glpk@gmx.de>

Date: Fri, 26 Oct 2012 12:03:02 UTC

Severity: normal

Found in version 3.99.2.1

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


🔗 View this message in rfc822 format

MIME-Version: 1.0
X-Mailer: MIME-tools 5.502 (Entity 5.502)
X-Loop: git-admin@x2go.org
From: git-admin@x2go.org (X2Go Bug Tracking System)
Subject: Bug#54 closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
 (Checksums added to X2Go tarball and binary downloads)
Message-ID: <handler.54.c.13517217272633.notifdone@bugs.x2go.org>
References: <20121031231525.15122ewa34wzb27x@mail.das-netzwerkteam.de>
X-X2go-PR-Message: they-closed 54
X-X2go-PR-Package: x2goclient
X-X2go-PR-Source: x2goclient
Date: Wed, 31 Oct 2012 22:18:02 +0000
Content-Type: multipart/mixed; boundary="----------=_1351721882-2746-0"
[Message part 1 (text/plain, inline)]
This is an automatic notification regarding your Bug report
which was filed against the x2goclient package:

#54: Missing signatures for downloads

It has been closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>.

Their explanation is attached below along with your original report.
If this explanation is unsatisfactory and you have not received a
better one in a separate message then please contact Mike Gabriel <mike.gabriel@das-netzwerkteam.de> by
replying to this email.


-- 
X2Go Bug Tracking System
Contact git-admin@x2go.org with problems
[Message part 2 (message/rfc822, inline)]
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: 54@bugs.x2go.org
Cc: 54-submitter@bugs.x2go.org, control@bugs.x2go.org
Subject: Checksums added to X2Go tarball and binary downloads
Date: Wed, 31 Oct 2012 23:15:25 +0100
[Message part 3 (text/plain, inline)]
close #54
thanks

Hi Heinrich, hi all,

I have just added MD5, SHA1 and GPG signatures to all X2Go source  
tarball and binary downloads.

@Developers, esp. Alex:

The commands to use in the future for new uploads on

  http://code.x2go.org/releases

are:

  $ md5sum $tarball > $tarball.md5
  $ sha1sum $tarball > $tarball.sha1
  $ gpg -a -b --sign $tarball

The uploading developers sign the uploaded tarballs with their own GPG  
keys so.

Mike

-- 

DAS-NETZWERKTEAM
mike gabriel, rothenstein 5, 24214 neudorf-bornstein
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 4 (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: "glpk xypron" <xypron.glpk@gmx.de>
To: submit@bugs.x2go.org
Subject: Missing signatures for downloads
Date: Fri, 26 Oct 2012 14:00:52 +0200
Package: x2goclient
Version: 3.99.2.1

Dear maintainer,

you offer downloads for the x2go client, e.g. on page
http://code.x2go.org/releases/binary-win32/x2goclient

Unfortunately you do not provide any possibility to verify if a downloaded file is authentic, or if during transfer a virus has been added.

Please, provide for each download a GPG signature and optionally SHA1 and MD5 hashs.

http://maven.apache.org/download.html
is a good examples except for the missing SHA1 hash. MD5 alone is not safe anymore.

Best regards

Heinrich Schuchardt

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Mon May 19 08:37:34 2025; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.