Automated signature verification for downloads

Werner Koch wk at gnupg.org
Wed Apr 23 08:35:30 CEST 2008


On Fri, 18 Apr 2008 23:26, anthonybryan at gmail.com said:

> .metalink files are XML and list mirrors, checksums, signatures, and
> other information, used for improving downloads and automating
> advanced features. There are about 20 metalink download clients, from
> CLI to GUI, on all platforms, from download managers to Web browsers.

I read the wikipedia article and brosed the emtalink site but was not
abale to find any speicification.  A list of supporting programs is not
that helpful to understand the format.

> Downloading to curl-7.18.1.tar.gz
> [#########################------------------------------] 47% 1.00/2.12 MB
> -----BEGIN PGP SIGNATURE INFORMATION-----
> timestamp: Sun, 30 Mar 2008 05:10:27 (Eastern Daylight Time)
> fingerprint: 914C533DF9B2ADA2204F586D78E11C6B279D5C91
> uid: Daniel Stenberg (Haxx) <daniel at haxx.se>
> -----END PGP SIGNATURE INFORMATION-----

I do not understand what this is about.  Using header lines very similar
to those defined by OpenPGP is a bit questionable.


Salam-Shalom,

   Werner

-- 
Die Gedanken sind frei.  Auschnahme regelt ein Bundeschgesetz.




More information about the Gnupg-users mailing list