Did anyone else experience similar issues? I'd like to make sure the
signatures and digest work fine before publishing the release.

Thanks

Jacopo

On Wed, Feb 14, 2024 at 8:57 AM Jacques Le Roux
<jacques.le.r...@les7arts.com> wrote:
>
> Hi,
>
> And this is what get on Ubuntu 20.04, better for SHA512 (but not right it 
> seems), weird for GPG. All that was working before, notably with last
> versions of apache-ofbiz-18.12.12.
>
> jacques@jacques-VirtualBox:~/ofbiz-tools$ ./verify-ofbiz-release.sh -v 
> apache-ofbiz-18.12.12  2>&1 | tee verify.log
> Processing files for release: apache-ofbiz-18.12.12...
> Verifying files...
> sha check of file: apache-ofbiz-18.12.12.zip
> Using sha file: apache-ofbiz-18.12.12.zip.sha512
> apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D 
> ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA
> 5F95A606 B1CC6C1A A8CBC42C
> apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D 
> ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA
> 5F95A606 B1CC6C1A A8CBC42C
> sha sums mismatch!
>
> GPG verification output
> gpg: Signature made jeu. 08 févr. 2024 11:03:49 CET
> gpg:                using RSA key 3545C5E31CC2D029B2CCAD067A580908847AF9E0
> gpg: Can't check signature: No public key
>
> Done processing files for release apache-ofbiz-18.12.12
>
> "sha sums mismatch!" sounds weird to me as the two lines compare
>
> Also I don't understand what's going on with GPG since I have both KEYS and 
> apache-ofbiz-18.12.12.zip.asc
>
> Do I miss something?
>
> Jacques
>
>
> Le 13/02/2024 à 14:09, Jacques Le Roux a écrit :
> > Since I'm on win7 using PowerShell:
> >
> >    PS C:\projectsASF\Git\ofbiz-framework\tools> Get-Filehash 
> > apache-ofbiz-18.12.12.zip -a SHA512
> >    Algorithm Hash Path
> >    --------- ---- ----
> >    SHA512 
> > D6CC35969BD53A4C34E267A9221AE76AF416E2A0D442A2195B16227F2A431B2CBDC... 
> > C:\projectsASF\Git\ofbiz-framework\tools\apache-ofbiz-18.12.12.zip
> >
> >    PS C:\projectsASF\Git\ofbiz-framework\tools> Get-Filehash 
> > apache-ofbiz-18.12.12.zip.sha512 -a SHA512
> >    Algorithm Hash Path
> >    --------- ---- ----
> >    SHA512 
> > EB5E9CEAF12777750D1D78BE0ADC9F729BCDBB90646EBFC7434F47EAEE73BCF5008...
> > C:\projectsASF\Git\ofbiz-framework\tools\apache-ofbiz-18.12.12.zip.sha512
> >
> > Not sure why it's different from verify-ofbiz-release.sh result :/
> >
> > Le 13/02/2024 à 13:51, Jacques Le Roux a écrit :
> >> Hi Jacopo,
> >>
> >> It seems there is at least a hash issue:
> >>
> >> sha check of file: apache-ofbiz-18.12.12.zip
> >> Using sha file: apache-ofbiz-18.12.12.zip.sha512
> >> apache-ofbiz-18.12.12.zip: D6CC3596 9BD53A4C 34E267A9 221AE76A F416E2A0 
> >> D442A219 5B16227F 2A431B2C BDCB0E05 87C334C6 19DB5EE4 ED0D1F21 5EC90253
> >> 88AB6487 DC5B71E7 5BA97A17
> >> apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D 
> >> ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA
> >> 5F95A606 B1CC6C1A A8CBC42C
> >> sha sums mismatch!
> >>
> >> Thanks
> >>
> >> Jacques
> >>
> >> Le 13/02/2024 à 09:34, Jacopo Cappellato a écrit :
> >>> This is the vote thread, third attempt, to publish "Apache OFBiz
> >>> 18.12.12", twelfth
> >>> release from the release18.12 branch.
> >>>
> >>> The release files can be downloaded from here:
> >>> https://dist.apache.org/repos/dist/dev/ofbiz/
> >>> and are:
> >>> * apache-ofbiz-18.12.12.zip
> >>> * KEYS: text file with keys
> >>> * apache-ofbiz-18.12.12.zip.asc: the detached signature file
> >>> * apache-ofbiz-18.12.12.zip.sha512: checksum file
> >>>
> >>> Please download and test the zip file and its signatures (for
> >>> instructions on testing the signatures see
> >>> http://www.apache.org/info/verification.html).
> >>>
> >>> Vote:
> >>> [ +1] release as Apache OFBiz 18.12.12
> >>> [ -1] do not release
> >>>
> >>> This vote is open for at least 5 days.
> >>>
> >>> For more details about this process please refer to
> >>> http://www.apache.org/foundation/voting.html

Reply via email to