From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 55165 invoked by alias); 29 Sep 2016 18:40:08 -0000 Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner@cygwin.com Mail-Followup-To: cygwin@cygwin.com Received: (qmail 55150 invoked by uid 89); 29 Sep 2016 18:40:07 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-0.0 required=5.0 tests=AWL,BAYES_00,EXECUTABLE_URI,KAM_EXEURI,RCVD_IN_DNSWL_LOW,SPF_PASS autolearn=no version=3.3.2 spammy=urgent, URGENT, cygwin@cygwin.com, pdt X-HELO: mail-in-13.arcor-online.net Received: from mail-in-13.arcor-online.net (HELO mail-in-13.arcor-online.net) (151.189.21.53) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Thu, 29 Sep 2016 18:39:57 +0000 Received: from mail-in-20-z2.arcor-online.net (mail-in-20-z2.arcor-online.net [151.189.8.85]) by mx.arcor.de (Postfix) with ESMTP id 3slNfM0yghz32wD for ; Thu, 29 Sep 2016 20:39:55 +0200 (CEST) Received: from mail-in-05.arcor-online.net (mail-in-05.arcor-online.net [151.189.21.45]) by mail-in-20-z2.arcor-online.net (Postfix) with ESMTP id 1EB358407B2 for ; Thu, 29 Sep 2016 20:39:55 +0200 (CEST) X-DKIM: Sendmail DKIM Filter v2.8.2 mail-in-05.arcor-online.net 3slNfL75Lbzmfq Received: from Gertrud (p54B7E8DF.dip0.t-ipconnect.de [84.183.232.223]) (Authenticated sender: stromeko@arcor.de) by mail-in-05.arcor-online.net (Postfix) with ESMTPSA id 3slNfL75Lbzmfq for ; Thu, 29 Sep 2016 20:39:54 +0200 (CEST) From: Achim Gratz To: cygwin@cygwin.com Subject: Re: URGENT: BAD signature from "Cygwin " References: <125363965.20160929001342@yandex.ru> Date: Thu, 29 Sep 2016 18:41:00 -0000 In-Reply-To: (Thomas Sanders's message of "Wed, 28 Sep 2016 22:58:50 +0000") Message-ID: <877f9uh7nt.fsf@Rainer.invalid> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1.50 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-SW-Source: 2016-09/txt/msg00394.txt.bz2 Thomas Sanders writes: > Thanks for the reply, here is the actual script. I must have copy/pasted the wrong info previously. > ### > wget -q http://cygwin.com/setup-x86.exe -O ${DESTINATION}/setup-x86.exe > wget -q http://cygwin.com/setup-x86.exe.sig -O ${DESTINATION}/setup-x86.exe.sig > wget -q http://cygwin.com/setup-x86_64.exe -O ${DESTINATION}/setup-x86_64.exe > wget -q http://cygwin.com/setup-x86_64.exe.sig -O ${DESTINATION}/setup-x86_64.exe.sig > wget -q http://cygwin.com/key/pubring.asc -O ${DESTINATION}/pubring.asc For checking the signatures to be of any real use, you'd need to use https at least. Also, you'd need to establish the provenance of the key independently. > testing /tftpboot/PXE/mirrors/cygwin//setup-x86.exe > gpg: Signature made Fri 09 Sep 2016 02:20:02 AM PDT using DSA key ID 676041BA > gpg: BAD signature from "Cygwin " BLODA, most likely. Particularly some stupid heuristic scanner that thinks that UPX compressed binaries are dangerous just because they use compression. Regards, Achim. -- +<[Q+ Matrix-12 WAVE#46+305 Neuron microQkb Andromeda XTk Blofeld]>+ Wavetables for the Terratec KOMPLEXER: http://Synth.Stromeko.net/Downloads.html#KomplexerWaves -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple