Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SHA256 file lists wrong hash for the file libressl.asc #1094

Open
jb-wisemo opened this issue Sep 10, 2024 · 1 comment
Open

SHA256 file lists wrong hash for the file libressl.asc #1094

jb-wisemo opened this issue Sep 10, 2024 · 1 comment

Comments

@jb-wisemo
Copy link

In the portable release download directory https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/, there is an SHA256 file helpfully providing hashes of most other files. Unfortunately, the hash of libressl.asc as downloaded by me doesn't match the hash of libressl.asc in the SHA256 as downloaded by me.

To me this indicates one of 3 problems:

A: Someone at the project failed to keep the files in sync with each other.
B: Someone nefarious changed the libressl.asc file to a fraudulent signing key.
C: Someone nefarious changed the SHA256 file to force this problem as part of some larger attack plan.

P.S., the SHA256 file seems to not list hashes for the *.tar.gz.asc files, which supposedly won't change unless some future security issue requires resigning all old releases with a new key or tool ONCE.

P.P.S., the SHA256 file format is nonstandard, but converting to standard md5sum/sha256sum format is a one line script and changing the official file would probably mess up some obscure OpenBSD specific tools, so just keep the nonstandard format for now.

@botovq
Copy link
Contributor

botovq commented Sep 10, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants