CTAN SHA512 Signature Mismatch

Norbert Preining norbert at preining.info
Mon Aug 12 17:06:31 CEST 2024


Hi

> Perhaps it is too early in the day, today, but I am trying to retrieve the
> windows tex-live installer and I had been unable to get a match on a SHA512
> digest of the executable.

Please wait a bit, there are often mirrors just in sync, and the sha
file and the actual exe might not both be synced already.

> I have not been able to reproduce this digest (4abe...) on the installer
> from subsequent CTAN tex-archive and texlive downloads. The texlive
> installer is presently reporting an 08-10-2024 on CTAN mirrors, tex-archive
> is reporting an 08-12-2024 date. Again, subsequent downloads are matching
> the GPG verified SHA512 digest.

Yes, that is a problem with the mirror update not being instantenous.

> I'm sorry to spam. I also wanted to note details on the public key (which
> has expired) used for the integrity checks mentioned.

No it hasn't, you haven't pulled updated signatures:

[~] gpg --list-key  D8F2F86057A857E42A88106A4CE1877E19438C70
pub   rsa2048/0x0D5E5D9106BAB6BC 2016-03-19 [SC]
      Key fingerprint = C78B 82D8 C795 12F7 9CC0  D7C8 0D5E 5D91 06BA B6BC
uid                   [  full  ] TeX Live Distribution <tex-live at tug.org>
sub   rsa2048/0x72A5E8C1B001980F 2016-03-19 [E]
sub   rsa2048/0x4CE1877E19438C70 2016-03-19 [S] [expires: 2025-06-25]


Expires 2025-06-25

Best regards

Norbert

--
PREINING Norbert                              https://www.preining.info
arXiv / Cornell University   +   IFMGA Guide   +   TU Wien  +  TeX Live
GPG: 0x860CDC13   fp: F7D8 A928 26E3 16A1 9FA0 ACF0 6CAC A448 860C DC13


More information about the tex-live mailing list.