Verifying 3.5.0.1 MSI file

Mark Scarbrough scarbrom at uci.edu
Mon Mar 17 14:45:57 UTC 2025


Totally agree with that. Always wondered about the sig file sitting right next to the download. But it is “best practice” to check the sig when it is published so I’m dutifully including that as an optional step.

-Mark

From: Cantor, Scott <cantor.2 at osu.edu>
Date: Monday, March 17, 2025 at 7:40 AM
To: Shib Users <users at shibboleth.net>
Cc: Mark Scarbrough <scarbrom at uci.edu>
Subject: Re: Verifying 3.5.0.1 MSI file
> Previous versions of the Shibboleth installer included a
> sha256 file that I was able to verify the download

I didn't realize I never generated them, it's done.

Having said which, checksums obviously prove nothing much of import, I wouldn't consider them verifying anything unless you get the checksum OOB, but of course if you verify the signature once and then get the checksum for that same file generated locally and posted somewhere, that's of value. But not when it's right next to the file that would be attacked.

-- Scott

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250317/57c63e91/attachment.htm>


More information about the users mailing list