Verifying 3.5.0.1 MSI file

Cantor, Scott cantor.2 at osu.edu
Mon Mar 17 14:40:41 UTC 2025


> Previous versions of the Shibboleth installer included a
> sha256 file that I was able to verify the download

I didn't realize I never generated them, it's done.

Having said which, checksums obviously prove nothing much of import, I wouldn't consider them verifying anything unless you get the checksum OOB, but of course if you verify the signature once and then get the checksum for that same file generated locally and posted somewhere, that's of value. But not when it's right next to the file that would be attacked.

-- Scott




More information about the users mailing list