Subject: pkg/11809: Checksums for packages
To: None <gnats-bugs@gnats.netbsd.org>
From: Dominik Rothert <dr@astorit.com>
List: netbsd-bugs
Date: 12/24/2000 06:02:15
>Number:         11809
>Category:       pkg
>Synopsis:       SHA1 checksums preferred
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    pkg-manager
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Sun Dec 24 06:02:00 PST 2000
>Closed-Date:
>Last-Modified:
>Originator:     Dominik Rothert
>Release:        NetBSD 1.5
>Organization:
ASTORIT
>Environment:
System: NetBSD domix 1.5 NetBSD 1.5 (DOMIX) #2: Fri Dec 22 23:12:56 CET 2000 root@domix:/usr/src/sys/arch/i386/compile/DOMIX i386

>Description:

MD5 is not the best hash algorithm. 
Instead of continue using MD5, we should consider using SHA1 (and MD5?)
hecksums. 

See <http://mail-index.netbsd.org/tech-pkg/2000/12/20/0011.html> and
<http://mail-index.netbsd.org/cgi-bin/htsearch?config=nbsdwww&restrict=&exclude=&method=and&format=builtin-long&sort=score&words=checksums+for+packages+dr%40astorit.com> for further information on this thread.

>How-To-Repeat:
>Fix:
>Release-Note:
>Audit-Trail:
>Unformatted: