Missing signature for cloud image checksum file

Ask for help with issues regarding the Installations of the Debian O/S.
Post Reply
Message
Author
Cam Eliot
Posts: 6
Joined: 2021-05-03 13:21

Missing signature for cloud image checksum file

#1 Post by Cam Eliot »

I am trying the verify the authenticity of the cloud image checksum files, but there seems to be no SHA512SUMS.sign file:

https://cloud.debian.org/images/cloud/bookworm/latest/

The conventional CD image directory seems to have one though:

https://cdimage.debian.org/debian-cd/cu ... 64/iso-cd/

Should there be a signature file for SHA512SUMS in the first directory? Or is there another way to verify its authenticity?

User avatar
fabien
Forum Helper
Forum Helper
Posts: 1158
Joined: 2019-12-03 12:51
Location: Anarres (Toulouse, France actually)
Has thanked: 101 times
Been thanked: 265 times

Re: Missing signature for cloud image checksum file

#2 Post by fabien »

https://cloud.debian.org/images/cloud/ says:
How can I verify my download is correct and exactly what has been created by Debian?

For the current official images (in the per-distribution directories), the safest method is to download the image and checksum files over TLS from cloud.debian.org or cdimage.debian.org. These names support DNSSEC, so a validating resolver can ensure that a client is connected to a Debian host. And TLS ensures that the data is not manipulated in flight.

The legacy OpenStack images (in the OpenStack/ directory) provide checksums and signatures. See SHA512SUMS.sign, etc. For more information about the verification steps, read the verification guide

If you're interested in contributing checksum signatures for the current images, please reach us on the list: debian-cloud at lists.debian.org.
ImageShare your Debian SCRIPTS
There will be neither barrier nor walls, neither official nor guard, there will be no more desert and the entire world will become a garden. — Anacharsis Cloots

Cam Eliot
Posts: 6
Joined: 2021-05-03 13:21

Re: Missing signature for cloud image checksum file

#3 Post by Cam Eliot »

I had assumed that checksum file signatures were an important piece of the verification process but it would appear the cloud images do not have them at the moment. Thank you for pointing me towards the right info.

Post Reply