Discussion:
Bug#1011261: The digest algorithm in SHA512SUMS.sign is SHA256
(too old to reply)
Zhang Boyang
2022-05-19 04:40:01 UTC
Permalink
Package: debian-cd

Hello,

I downloaded debian iso and its SHA512SUMS file. However, when I use gpg
to verify authenticity of SHA512SUMS, I found the signature file use
SHA256 as its digest algorithm. Although SHA256 is pretty safe, it's
seem strange that sign a SHA512SUMS with SHA256. I think it's better to
sign SHA512SUMS with SHA512.

Best Regards,
Zhang Boyang


$ LANG=C gpg -v --verify SHA512SUMS.sign
gpg: assuming signed data in 'SHA512SUMS'
gpg: Signature made Sun Mar 27 05:22:41 2022 CST
gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: using pgp trust model
gpg: Good signature from "Debian CD signing key
<debian-***@lists.debian.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the
owner.
Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B
gpg: binary signature, digest algorithm SHA256, key algorithm rsa4096
Debian Bug Tracking System
2022-05-22 00:00:01 UTC
Permalink
severity -1 minor
Bug #1011261 [debian-cd] The digest algorithm in SHA512SUMS.sign is SHA256
Severity set to 'minor' from 'normal'
--
1011261: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1011261
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Steve McIntyre
2022-05-22 00:00:01 UTC
Permalink
Control: severity -1 minor
Post by Zhang Boyang
Package: debian-cd
Hello,
I downloaded debian iso and its SHA512SUMS file. However, when I use gpg to
verify authenticity of SHA512SUMS, I found the signature file use SHA256 as
its digest algorithm. Although SHA256 is pretty safe, it's seem strange that
sign a SHA512SUMS with SHA256. I think it's better to sign SHA512SUMS with
SHA512.
Maybe. It's not really a priority to change anything here right now,
I'll be honest...
--
Steve McIntyre, Cambridge, UK. ***@einval.com
There's no sensation to compare with this
Suspended animation, A state of bliss
Loading...