Page MenuHomeVyOS Platform

Remove MD5 sums from the image
Closed, ResolvedPublic

Description

Long ago, we added support for SHA-256 checksums to the live CD integrity check mechanism. That change was always a bit of a "security theater" — it's about the built-in check that simply verifies that the image was not accidentally corrupted, so even CRC sums wouldn't be that bad for that purpose. It's just that any use of a really old HMAC algorithm gives people (myself included) a knee jerk reaction.

In any case, we never removed MD5 sums, for some reason — only added SHA-256. I checked that removing them doesn't break anything, even direct upgrade from 1.3.8 is unaffected, so it's time to remove them.

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Internal change (not visible to end users)

Event Timeline

c-po moved this task from Need Triage to Completed on the VyOS Rolling board.
c-po moved this task from Open to Finished on the VyOS 1.5 Circinus board.