From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.bugs Subject: bug#55666: enhancement request - SHA-256 for emacs downloads Date: Sat, 28 May 2022 09:15:23 +0300 Message-ID: <83czfymbd0.fsf@gnu.org> References: <875ylr8cmq.fsf@gnus.org> <835ylrnor3.fsf@gnu.org> Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="12293"; mail-complaints-to="usenet@ciao.gmane.io" Cc: larsi@gnus.org, 55666@debbugs.gnu.org To: Ali Elshishini , Corwin Brust Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Sat May 28 08:16:35 2022 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1nupkZ-00033Q-BG for geb-bug-gnu-emacs@m.gmane-mx.org; Sat, 28 May 2022 08:16:35 +0200 Original-Received: from localhost ([::1]:36316 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nupkX-0005Jv-Rs for geb-bug-gnu-emacs@m.gmane-mx.org; Sat, 28 May 2022 02:16:33 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:46572) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nupk2-0005Ic-4t for bug-gnu-emacs@gnu.org; Sat, 28 May 2022 02:16:02 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:42350) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1nupk1-0001Gq-SN for bug-gnu-emacs@gnu.org; Sat, 28 May 2022 02:16:01 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1nupk1-0001V2-KC for bug-gnu-emacs@gnu.org; Sat, 28 May 2022 02:16:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Eli Zaretskii Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sat, 28 May 2022 06:16:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55666 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: wontfix Original-Received: via spool by 55666-submit@debbugs.gnu.org id=B55666.16537185465744 (code B ref 55666); Sat, 28 May 2022 06:16:01 +0000 Original-Received: (at 55666) by debbugs.gnu.org; 28 May 2022 06:15:46 +0000 Original-Received: from localhost ([127.0.0.1]:36247 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nupjm-0001Ua-9f for submit@debbugs.gnu.org; Sat, 28 May 2022 02:15:46 -0400 Original-Received: from eggs.gnu.org ([209.51.188.92]:53224) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nupji-0001UL-Gf for 55666@debbugs.gnu.org; Sat, 28 May 2022 02:15:45 -0400 Original-Received: from fencepost.gnu.org ([2001:470:142:3::e]:52278) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nupjS-000186-O4; Sat, 28 May 2022 02:15:36 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=References:Subject:In-Reply-To:To:From:Date: mime-version; bh=r/egZtAIhXb71SFMaWQe/610mTvGp/a9DngEOxXeNbo=; b=MSRmn9pZhaMr 0TaK7YiYKRJKfC0M3Fo5+o5C3+83UJjmwacBef7uV4iwbB3PF9J7J2HUB8sVJjZ7hOtVHUkEkhtc2 EZvwakgAliBacyix5Rj1e1C3vXf4QXY3htx9X9uO7TSO8mn2GKafZaHhLtnVHhruCTn6EV7oNq+ry 8aZDbTv/N+V/U1+iRsmbZIOvHExlhyz8LzJSdhQRpPgQ+EyULbkgNt0CgJqoR+dGisBK9IMkO59mI Owz+/xtdBK/aTERndPzToHIBNBqxKDnZuBHcmxoG76MdoFLXg+MeOQaQga4+eJL7AoP8eL+b4BMUh SKzKeg/AtD58S+9bry9Dog==; Original-Received: from [87.69.77.57] (port=1944 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nupjS-00061K-36; Sat, 28 May 2022 02:15:26 -0400 In-Reply-To: (message from Ali Elshishini on Sat, 28 May 2022 00:43:28 +0000) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:233234 Archived-At: > From: Ali Elshishini > CC: "55666@debbugs.gnu.org" <55666@debbugs.gnu.org> > Date: Sat, 28 May 2022 00:43:28 +0000 > > Thanks for pointing out the announcement email > Unfortunately it doesn't include the SHA hashes for the windows files You never said in your original message that this is about the Windows binaries. The Windows precompiled binaries are produced by volunteers who are only loosely associated with the Emacs project. The project releases Emacs as source tarballs, and the SHA checksums for that are in the announcement. I've CC'ed Corwin, who produced the latest binaries of Emacs 28.1. For the Windows binaries, providing the SHA checksums is entirely up to the person(s) who makes the binaries available. > Also verify the signature on windows I am not sure if this is the expected output > for me look like it failed > > >From command line > > PS C:\downloads> C:\"Program Files (x86)"\GnuPG\bin\gpg --keyserver keyserver.ubuntu.com --recv-keys > 17E90D521672C04631B1183EE78DAE0F3115E06B > gpg: key E78DAE0F3115E06B: "Eli Zaretskii " not changed > gpg: Total number processed: 1 > gpg: unchanged: 1 > PS C:\downloads> C:\"Program Files (x86)"\GnuPG\bin\gpg --verify .\emacs-28.1.zip.sig > gpg: assuming signed data in '.\emacs-28.1.zip' > gpg: Signature made 2022-04-21 4:11:30 PM Eastern Daylight Time > gpg: using RSA key ECE77CF417C76C1ACFCE7C2B5B6135511580F007 > gpg: Can't check signature: No public key > PS C:\downloads> You are using the wrong GPG key: my key was used to sign the source tarballs, not the Windows binary zip files. The Windows binaries were signed by Corwin Brust's key as the Download page says. You need to fetch that key, not mine. > I think adding the SHA hashes somewhere remains a valuable addition > using and verifying signature on windows is more complicated than it needs to be That may be so, but this activity is based on volunteers doing this on their free time. We can only ask them to do what their time and resources allow.