Package: ftp.debian.org
Severity: wishlist

Hi,

the debian installer images are weakly checksummed in

  dists/*/*/installer-*/*/images/MD5SUMS

It would be nice if sha checksums and sizes would be added like
everywhere else.

More importantly though the MD5SUMS files are not indexed in the
Release/Release.gpg files and can thus not be trusted. This also means
that mirroring tools like debmirror can not mirror all the image dirs
except the current dir. Getting the names of the other dirs is not
generally possible.


So please add the MD5SUMS files to the Release file so a proper trust
path is established and recommend to the D-I team to provide a better
checksum file with sha checksums and sizes.

MfG
        Goswin



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to