Re: Re: Re: package.xml: md5sum attribute of <file />
| From: | Jon Parise | Date: | Mon, 24 Nov 2003 18:35:14 +0000 |
| Subject: | Re: Re: Re: package.xml: md5sum attribute of <file /> | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-23833@lists.php.net to get a copy of this message | ||
On Mon, Nov 24, 2003 at 07:11:07PM +0100, Roman Neuhauser wrote:
> > It gives the PEAR Installer a mechanism by which to validate the
> > individual files that it's about to place on the user's disk.
>
> what exactly does "validate" mean in the above sentence? or is
> emphasis on the word "individual"?
The emphasis is on "individual". The manifest is the package.xml
file, which is stored in and distributed with the package archive.
Therefore, the package.xml file can have no knowledge of the overall
integrity of the package archive, but it can verify that the
individual files are valid based on their MD5 checksums.
I suppose this mechanism it more about package integrity and less
about security. The proposed solution to the security problem
involves digitally signing the package and having the PEAR Installer
verify the signature after downloading the archive.
--
Jon Parise (jon@php.net) :: The PHP Project (http://www.php.net/)