From owner-freebsd-ports@FreeBSD.ORG Sun Dec 18 18:28:04 2005 Return-Path: X-Original-To: ports@freebsd.org Delivered-To: freebsd-ports@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D1A2016A41F for ; Sun, 18 Dec 2005 18:28:04 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from elvis.mu.org (elvis.mu.org [192.203.228.196]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8692343D72 for ; Sun, 18 Dec 2005 18:28:04 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from obsecurity.dyndns.org (elvis.mu.org [192.203.228.196]) by elvis.mu.org (Postfix) with ESMTP id CC4ED1A3C1A; Sun, 18 Dec 2005 10:28:03 -0800 (PST) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id E68A551589; Sun, 18 Dec 2005 13:28:02 -0500 (EST) Date: Sun, 18 Dec 2005 13:28:02 -0500 From: Kris Kennaway To: Igor Pokrovsky Message-ID: <20051218182802.GA21549@xor.obsecurity.org> References: <20051218181222.GA9375@doom.homeunix.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="/9DWx/yDrRhgMJTb" Content-Disposition: inline In-Reply-To: <20051218181222.GA9375@doom.homeunix.org> User-Agent: Mutt/1.4.2.1i Cc: ports@freebsd.org Subject: Re: SHA256 checksum in ports X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 18 Dec 2005 18:28:04 -0000 --/9DWx/yDrRhgMJTb Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Dec 18, 2005 at 09:12:22PM +0300, Igor Pokrovsky wrote: > Hi, >=20 > Is anyone knows what was the reason to add SHA256 checksum check > in ports? Why MD5 was insufficient? Enough progress has been made towards breaking MD5 that it is no longer considered safe to rely on for these purposes. Kris --/9DWx/yDrRhgMJTb Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFDpaoyWry0BWjoQKURAuMBAKDy++f9yPpnhtQwjtdgXMHeAJIOxACfRGP1 tmQFb2H1j5acATY97+NW8IM= =Lv43 -----END PGP SIGNATURE----- --/9DWx/yDrRhgMJTb--