CTAN SHA512 Signature Mismatch

Nathan Edwards nathan.william.edwards.1993 at gmail.com
Mon Aug 12 09:31:53 CEST 2024


  Dear TeX User Group tex-live Supporter(s),

I'm sorry to spam. I also wanted to note details on the public key (which
has expired) used for the integrity checks mentioned.

*gpg -k*
[keyboxd]
---------
pub   rsa2048 2016-03-19 [SC]
      C78B82D8C79512F79CC0D7C80D5E5D9106BAB6BC

*gpg --check-signatures*
[keyboxd]
---------
pub   rsa2048 2016-03-19 [SC]
      C78B82D8C79512F79CC0D7C80D5E5D9106BAB6BC
uid           [ unknown] TeX Live Distribution <tex-live at tug.org>
sig!3        0D5E5D9106BAB6BC 2016-03-19  [self-signature]
sig!3        0D5E5D9106BAB6BC 2016-03-19  [self-signature]
sub   rsa2048 2016-03-19 [E]
sig!         0D5E5D9106BAB6BC 2016-03-19  [self-signature]

*gpg --verify .\install-tl-windows.exe.sha512.asc
.\install-tl-windows.exe.sha512*
gpg: Signature made 08/10/24 19:56:11 Eastern Daylight Time
gpg:                using RSA key D8F2F86057A857E42A88106A4CE1877E19438C70
gpg: Good signature from "TeX Live Distribution <tex-live at tug.org>"
[unknown]
gpg: Note: This key has expired!
Primary key fingerprint: C78B 82D8 C795 12F7 9CC0  D7C8 0D5E 5D91 06BA B6BC
     Subkey fingerprint: D8F2 F860 57A8 57E4 2A88  106A 4CE1 877E 1943 8C70

Sincerely,
Nathan

On Mon, Aug 12, 2024 at 3:11 AM Nathan Edwards <
nathan.william.edwards.1993 at gmail.com> wrote:

> Dear TeX User Group tex-live Supporter(s),
>
> Perhaps it is too early in the day, today, but I am trying to retrieve the
> windows tex-live installer and I had been unable to get a match on a SHA512
> digest of the executable.
>
> I retrieved the installer from:
> https://mirror.ctan.org/systems/texlive/tlnet/install-tl-windows.exe
> https://ctan.org/tex-archive/systems/texlive/tlnet
>
> I verified  GPG integrity on the exe.SHA512 digest file from tex-archive
> with the GPG public key, https://tug.org/texlive/files/texlive.asc . The
> mirror exe.SHA512 digests match this digest.
>
> For some reason, though, given the following SHA512 digest in
> systems/texlive and tex-archive:
>
> install-tl-windows.exe.sha512 <https://ctan.math.illinois.edu/systems/texlive/tlnet/install-tl-windows.exe.sha512>
>
> 6fd3ddede8328f2d6af979055c94b2d5231e872fbfaebef603690d780aa54557b3368b253d1063700cd297c65c65c05e87e113710e0985a6bc79f430862b8677
>  install-tl-windows.exe
>
> I am receiving a different SHA512 digest of the installer executable.
> 4abcedb05cbb6af6125a37e7a02d11f7f8e90025a5c82f29466d5ee3a2df1a76a0dd7802d0bd05e9aa8f0ec59f98bef673d8520bdb23163a237fbb7dbab0f8f1
> install-tl-windows.exe
>
> I have not been able to reproduce this digest (4abe...) on the installer
> from subsequent CTAN tex-archive and texlive downloads. The texlive
> installer is presently reporting an 08-10-2024 on CTAN mirrors, tex-archive
> is reporting an 08-12-2024 date. Again, subsequent downloads are matching
> the GPG verified SHA512 digest.
>
> Thank you for your time.
>
> Cheers,
> Nathan
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://tug.org/pipermail/tex-live/attachments/20240812/b7bddc47/attachment.htm>


More information about the tex-live mailing list.