Uploaded image for project: 'Cocoon'
  1. Cocoon
  2. COCOON-2370

Download page gpg example needs second parameter

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • * Cocoon Core
    • None

    Description

      It is important that the file being checked is also specified [1] on the gpg command line [2]

      If the second paramater is omitted, gpg can report success without actually checking the main artifact. This should not happen on correctly constructed ASF downloads, as we only provide detached sigs, but we should not be documenting bad practise.

      [1] https://www.apache.org/info/verification.html#specify_both
      [2] http://cocoon.apache.org/mirror.html

      Attachments

        Activity

          People

            Unassigned Unassigned
            sebb Sebb
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated: