Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Where are the hashes for verification of download?

Ask for help with issues regarding the Installations of the Debian O/S.
Post Reply
Message
Author
kcbagr
Posts: 53
Joined: 2016-09-22 18:10

Where are the hashes for verification of download?

#1 Post by kcbagr »

I downloaded the minimal CD iso. Where can I find a PGP signed page of SHA256 or SHA512 hashes for verification?

It says at https://www.debian.org/CD/verify: "Cryptographically strong checksum algorithms (SHA256 and SHA512) are available for every releases"

Where? I downloaded from here (https://www.debian.org/CD/netinst/) and cannot find a PGP signed page of hashes.

User avatar
orythem27
Posts: 252
Joined: 2017-05-11 07:59
Location: P.R. China

Re: Where are the hashes for verification of download?

#2 Post by orythem27 »

It's in the folder containing the image. e.g.:
https://cdimage.debian.org/debian-cd/cu ... 64/iso-cd/

kcbagr
Posts: 53
Joined: 2016-09-22 18:10

Re: Where are the hashes for verification of download?

#3 Post by kcbagr »

orythem27 wrote:It's in the folder containing the image. e.g.:
https://cdimage.debian.org/debian-cd/cu ... 64/iso-cd/
I clicked the link to download the ISO at this page: https://www.debian.org/CD/netinst/. An ISO was downloaded to my desktop (no folder). Which folder are your referring?

How does one find the hashes from where I downloaded the ISO? Or is there no way?

User avatar
orythem27
Posts: 252
Joined: 2017-05-11 07:59
Location: P.R. China

Re: Where are the hashes for verification of download?

#4 Post by orythem27 »

kcbagr wrote:I clicked the link to download the ISO at this page: https://www.debian.org/CD/netinst/ ... How does one find the hashes from where I downloaded the ISO?
It's not obvious, so I thinks it's normal that you are unable to find it at first glance. Right click the download link ("amd64/i386/..."), select "Copy link address", open a new tab, paste the link, and remove the file name to enter the parent folder.

There might be a better way though. I, too, could not find an obvious link to the hashes on that page. Maybe we are both blind... :roll:

kcbagr
Posts: 53
Joined: 2016-09-22 18:10

Re: Where are the hashes for verification of download?

#5 Post by kcbagr »

orythem27 wrote:
kcbagr wrote:I clicked the link to download the ISO at this page: https://www.debian.org/CD/netinst/ ... How does one find the hashes from where I downloaded the ISO?
It's not obvious, so I thinks it's normal that you are unable to find it at first glance. Right click the download link ("amd64/i386/..."), select "Copy link address", open a new tab, paste the link, and remove the file name to enter the parent folder.

There might be a better way though. I, too, could not find an obvious link to the hashes on that page. Maybe we are both blind... :roll:
Okay. Debian's setup for finding the hashes is not helpful for noobs :0

Your technique works, though. thanks!

User avatar
orythem27
Posts: 252
Joined: 2017-05-11 07:59
Location: P.R. China

Re: Where are the hashes for verification of download?

#6 Post by orythem27 »

Thumbs up for your safety awareness on insisting to verify the downloaded image. Although reminded again and again, to this day, I still don't bother checking hashes most of the time. So, shame on me, maybe you wouldn't trust me as an iOS developer. :mrgreen:

kcbagr
Posts: 53
Joined: 2016-09-22 18:10

Re: Where are the hashes for verification of download?

#7 Post by kcbagr »

orythem27 wrote:Thumbs up for your safety awareness on insisting to verify the downloaded image. Although reminded again and again, to this day, I still don't bother checking hashes most of the time. So, shame on me, maybe you wouldn't trust me as an iOS developer. :mrgreen:
You definitely should verify :-) It's clear that governments are actively trying to compromise people's OSes, which leads to everyone's insecurity.

Post Reply