// COMPLETE THREAD

Re: Warning for PGP Users!

2 expanded posts ยท every known parent and child

NODE f35ece08Re: Warning for PGP Users!
>Each new
>version of PGP should contain a file with MD5 hashes of each of the
>source files, and the whole file with MD5 hash should be clearsigned
>by one of the developers (Branko, I think).

I checked the .tar file at soda.berkeley.edu and the sources have
several mismatching MD5s.  Is anyone looking at this?

 - Carl
NODE ca40ff40Re: Warning for PGP Users!
> I checked the .tar file at soda.berkeley.edu and the sources have
> several mismatching MD5s.  Is anyone looking at this?

Yes, the PGP 2.3A distribution has incorrect MD5 values in
contrib/md5sum/pgp23.md5. I think that they were not updated to acount for
the changes between versions 2.3 and 2.3A. 

Nevertheless, the file pgp23sigA.asc (which is distributed separately from
the .tar.Z and .zip files) contains good detached signatures from Colin
Plumb, covering the various .zip and .tar.Z files for PGP 2.3A.  

--apb (Alan Barrett)