[lug] kernel.org FC12 checksums

Kevin Fenzi kevin at scrye.com
Wed Nov 18 15:55:44 MST 2009


On Wed, 18 Nov 2009 15:27:44 -0700
Davide Del Vento <davide.del.vento at gmail.com> wrote:

> You are not alone (although I didn't myself, but heard from several
> friends). I believe whoever made this mistake has caused one of the
> biggest waste of time and bandwidth in recent times. Maybe they'll cut
> his/her hands (just kidding, of course :-)

It's not an error, it's just confusing. 

The checksum is a sha256 one. 
It's signed with a gpg signature which is sha1. 

The https://fedoraproject.org/en/verify page clearly says to use
sha256sum to verify the checksum. ;( 

Anyhow, it will hopefully get corrected next release to at least add a
note there about the sha1 being only the gpg sig. 

Also, mirrors.tummy.com has the f12 content.
We've uploaded a bunch of it since release. ;) 

kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
URL: <http://lists.lug.boulder.co.us/pipermail/lug/attachments/20091118/3ac80c6d/attachment.pgp>


More information about the LUG mailing list