Verification of downloads/updates

Status
Not open for further replies.
Joined
Jul 25, 2016
Messages
2
Hi,

Can somebody reassure me that the in GUI updates are verified using something more reliable than a sha256 checksum downloaded over the same unencrypted link as the update.

Also what is a reliable way of getting the checksum for new installs. ?

I notice that the documentation is/can be served over SSL but the download page at

http://www.freenas.org/download-freenas-release/

redirects to http when https us used.


The checksum shown there at present,

2628ef070ee8d50c0e3c2944766f5e8418c51d5aaf6d1e6a4239942372d1c11f

currently only shows up in one place on a Google search and that is not @freenas.org

Matthew
 

m0nkey_

MVP
Joined
Oct 27, 2015
Messages
2,739
You could always put in a feature request for it. Doesn't sound unreasonable to do. I've tested the URL and it does indeed appear to work over SSL.
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
The updates themselves are signed, too, IIRC.
 
Status
Not open for further replies.
Top