Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Offer to download checksum & detached GPG signature for Pop!_OS ISO's #328

Open
taivlam opened this issue May 7, 2024 · 0 comments
Open

Comments

@taivlam
Copy link
Contributor

taivlam commented May 7, 2024

Would it be possible to show SHA256 checksum and detached GPG signature files on the website for Pop!_OS ISO's?

From Reddit, in Source 1, the SHA256 checksums are mentioned to be saved in a separately generated SHA256SUMS file; while in Source 2 there is mention of additional safety in using GPG verification:

Using this, it's possible to deduce the SHA256SUMS and detached GPG signature SHA256SUMS.gpg exist in the same directory of any chosen ISO on the Pop!_OS site, as shown in this gist that goes through how to check the integrity and authenticity any downloaded Pop!_OS ISO.

This would be in line with Linux Mint's doc page for pre-install checks on downloaded ISO's.

So, the infrastructure for GPG verification exists, though it would be a bit easier if the detached checksums and GPG signatures were included with the Pop!_OS downloads for those who know &/or are able to use GPG verification. I'm aware this doesn't solve all security issues and is advanced for most Pop!_OS users. If there is a concern that this would also need in the installation documentation, I'd be willing to propose simply worded documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant