Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Time for PGP signed sha256sums?

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 263 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tkerin
      last edited by stephenw10

      Previous discussion of this topic can be found here: https://forum.netgate.com/topic/60535/pfsense-image-hashes-folly

      I've been looking around for mechanisms to verify the initial pfSense download, and it seems the sha256 sums are available for download from either https://files.pfsense.org/hashes/ or https://nyifiles.pfsense.org/mirror/downloads/ however there are no signature verification mechanisms which would authenticate the published hashes as genuine.

      Previous discussions have pointed out that the web update facility does perform a signature check, but let me pose it like this: if you initially install a backdoored pfsense version it's doesn't have to perform a signature verification check.. it can just pretend to install updates.

      I think being able to authenticate the initial pfsense download is pretty important. Without this, should an attacker compromise these servers they can recalculate the sha256sums of their backdoored pfsense version without detection.

      1 Reply Last reply Reply Quote 1
      • S
        silmor_senedlen
        last edited by

        I also think that PGP signature for sums or ISO image are needed.
        It will also allow to verify locally the integrity and authenticity of install images, stored in the environment without access to the Internet.
        And I think that efforts required to implement this is not so high to discard this idea.
        Many users who put security at the forefront, will be grateful.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.