[ 
https://issues.apache.org/jira/browse/GORA-71?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13176000#comment-13176000
 ] 

Lewis John McGibbney commented on GORA-71:
------------------------------------------

Hi Guys. To address this issue I think we are going to need to reconsider our 
formatting approach for releases.xml [1]. Pointing guys to the KEYS file is no 
problem as this can be specified as [2], however pointing them to the md5 
distros (which is what I am interpreting as 'links for hashes') is going to be 
slightly harder as it appears we haven't published any md5 distros to date!!!

Linking from ASF hosts is not going to be a problem as they resolve themselves 
similar to [2]

Checking sigs and hashes should be added to releases.xml similar to [3], but 
maybe not quite as detailed.... we don't want to scare people off :0)

Can I get thoughts on this please, specifially relating to creating and 
publishing the hashes? I am treading on deep water in this area and could do 
with some guidance. Thank you.

[1] 
https://svn.apache.org/repos/asf/incubator/gora/site/author/src/documentation/content/xdocs/releases.xml
 
[2] http://www.apache.org/dyn/closer.cgi/incubator/gora/KEYS
[3] http://httpd.apache.org/download.cgi
                
> Download page does not include pointer to KEYS file or hashes
> -------------------------------------------------------------
>
>                 Key: GORA-71
>                 URL: https://issues.apache.org/jira/browse/GORA-71
>             Project: Gora
>          Issue Type: Bug
>            Reporter: Sebb
>            Assignee: Lewis John McGibbney
>            Priority: Critical
>
> The download page includes a link to the archive and its gpg signatiure, but 
> there is no link to the KEYS file nor any links for hashes.
> These must all be linked from ASF hosts.
> Also, the download directory contains a zip archive, but this is not listed 
> on the download page.
> The download page should also give information on how to check sigs and 
> hashes.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to