Did anyone else experience similar issues? I'd like to make sure the signatures and digest work fine before publishing the release.
Thanks Jacopo On Wed, Feb 14, 2024 at 8:57 AM Jacques Le Roux <jacques.le.r...@les7arts.com> wrote: > > Hi, > > And this is what get on Ubuntu 20.04, better for SHA512 (but not right it > seems), weird for GPG. All that was working before, notably with last > versions of apache-ofbiz-18.12.12. > > jacques@jacques-VirtualBox:~/ofbiz-tools$ ./verify-ofbiz-release.sh -v > apache-ofbiz-18.12.12 2>&1 | tee verify.log > Processing files for release: apache-ofbiz-18.12.12... > Verifying files... > sha check of file: apache-ofbiz-18.12.12.zip > Using sha file: apache-ofbiz-18.12.12.zip.sha512 > apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D > ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA > 5F95A606 B1CC6C1A A8CBC42C > apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D > ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA > 5F95A606 B1CC6C1A A8CBC42C > sha sums mismatch! > > GPG verification output > gpg: Signature made jeu. 08 févr. 2024 11:03:49 CET > gpg: using RSA key 3545C5E31CC2D029B2CCAD067A580908847AF9E0 > gpg: Can't check signature: No public key > > Done processing files for release apache-ofbiz-18.12.12 > > "sha sums mismatch!" sounds weird to me as the two lines compare > > Also I don't understand what's going on with GPG since I have both KEYS and > apache-ofbiz-18.12.12.zip.asc > > Do I miss something? > > Jacques > > > Le 13/02/2024 à 14:09, Jacques Le Roux a écrit : > > Since I'm on win7 using PowerShell: > > > > PS C:\projectsASF\Git\ofbiz-framework\tools> Get-Filehash > > apache-ofbiz-18.12.12.zip -a SHA512 > > Algorithm Hash Path > > --------- ---- ---- > > SHA512 > > D6CC35969BD53A4C34E267A9221AE76AF416E2A0D442A2195B16227F2A431B2CBDC... > > C:\projectsASF\Git\ofbiz-framework\tools\apache-ofbiz-18.12.12.zip > > > > PS C:\projectsASF\Git\ofbiz-framework\tools> Get-Filehash > > apache-ofbiz-18.12.12.zip.sha512 -a SHA512 > > Algorithm Hash Path > > --------- ---- ---- > > SHA512 > > EB5E9CEAF12777750D1D78BE0ADC9F729BCDBB90646EBFC7434F47EAEE73BCF5008... > > C:\projectsASF\Git\ofbiz-framework\tools\apache-ofbiz-18.12.12.zip.sha512 > > > > Not sure why it's different from verify-ofbiz-release.sh result :/ > > > > Le 13/02/2024 à 13:51, Jacques Le Roux a écrit : > >> Hi Jacopo, > >> > >> It seems there is at least a hash issue: > >> > >> sha check of file: apache-ofbiz-18.12.12.zip > >> Using sha file: apache-ofbiz-18.12.12.zip.sha512 > >> apache-ofbiz-18.12.12.zip: D6CC3596 9BD53A4C 34E267A9 221AE76A F416E2A0 > >> D442A219 5B16227F 2A431B2C BDCB0E05 87C334C6 19DB5EE4 ED0D1F21 5EC90253 > >> 88AB6487 DC5B71E7 5BA97A17 > >> apache-ofbiz-18.12.12.zip: 67AA5932 53FFF35F 3AA89DC9 73951B33 8396F95D > >> ECF26EBD 1DB58C66 50EE37E5 D053CD02 C9CB3FC4 B06D8CCC 747FAAA1 45B251CA > >> 5F95A606 B1CC6C1A A8CBC42C > >> sha sums mismatch! > >> > >> Thanks > >> > >> Jacques > >> > >> Le 13/02/2024 à 09:34, Jacopo Cappellato a écrit : > >>> This is the vote thread, third attempt, to publish "Apache OFBiz > >>> 18.12.12", twelfth > >>> release from the release18.12 branch. > >>> > >>> The release files can be downloaded from here: > >>> https://dist.apache.org/repos/dist/dev/ofbiz/ > >>> and are: > >>> * apache-ofbiz-18.12.12.zip > >>> * KEYS: text file with keys > >>> * apache-ofbiz-18.12.12.zip.asc: the detached signature file > >>> * apache-ofbiz-18.12.12.zip.sha512: checksum file > >>> > >>> Please download and test the zip file and its signatures (for > >>> instructions on testing the signatures see > >>> http://www.apache.org/info/verification.html). > >>> > >>> Vote: > >>> [ +1] release as Apache OFBiz 18.12.12 > >>> [ -1] do not release > >>> > >>> This vote is open for at least 5 days. > >>> > >>> For more details about this process please refer to > >>> http://www.apache.org/foundation/voting.html