Re: Re: Re: package.xml: md5sum attribute of <file />

From: Date: Mon, 24 Nov 2003 18:35:14 +0000
Subject: Re: Re: Re: package.xml: md5sum attribute of <file />
References: 1 2 3 4 5  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-23833@lists.php.net to get a copy of this message
On Mon, Nov 24, 2003 at 07:11:07PM +0100, Roman Neuhauser wrote: > > It gives the PEAR Installer a mechanism by which to validate the > > individual files that it's about to place on the user's disk. > > what exactly does "validate" mean in the above sentence? or is > emphasis on the word "individual"? The emphasis is on "individual". The manifest is the package.xml file, which is stored in and distributed with the package archive. Therefore, the package.xml file can have no knowledge of the overall integrity of the package archive, but it can verify that the individual files are valid based on their MD5 checksums. I suppose this mechanism it more about package integrity and less about security. The proposed solution to the security problem involves digitally signing the package and having the PEAR Installer verify the signature after downloading the archive. -- Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)

« previous php.pear.dev (#23833) next »