Skip to content

Add digest for Qubes OS 4.3.1-rc1#97

Open
andrewdavidwong wants to merge 1 commit into
mainfrom
4.3.1-rc1
Open

Add digest for Qubes OS 4.3.1-rc1#97
andrewdavidwong wants to merge 1 commit into
mainfrom
4.3.1-rc1

Conversation

@andrewdavidwong

@andrewdavidwong andrewdavidwong commented May 28, 2026

Copy link
Copy Markdown
Member

@parulin

parulin commented May 31, 2026

Copy link
Copy Markdown

I don't know the process for generating digest files, so maybe it's not the time to fix it, but this issue is still open: QubesOS/qubes-issues#10512

@andrewdavidwong

Copy link
Copy Markdown
Member Author

I don't know the process for generating digest files, so maybe it's not the time to fix it, but this issue is still open: QubesOS/qubes-issues#10512

Yes, I had the same thought. If it were up to me, this digest would have a detached signature instead of being clearsigned, but it's not up to me, since I don't control the signing keys. I simply observed that this clearsigned 4.3.1-rc1 digest file was generated and uploaded to https://ftp.qubes-os.org/iso/. I then reasoned that, given that the digest exists, it probably doesn't make sense for it be on the FTP server but not in the secpack, so I opened this PR to add it to the secpack for the sake of consistency.

Until I receive information to the contrary, I continue to assume that detached-sig digests are coming in due course and that the security team just needs some more time to implement them.

@marmarek

Copy link
Copy Markdown
Member

QubesOS/qubes-builderv2#247

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants