From 0b2264d3d4a0c53917c6f64ae1d7e10b613e59de Mon Sep 17 00:00:00 2001 From: "Yann E. MORIN" Date: Thu, 3 Jul 2014 21:36:23 +0200 Subject: [PATCH] package/ca-certificates: add tarball's hashes ca-certificates contains sensitive security-related information, and we want to ensure the archive that we download has not been compromised. Add the sha1 and sha256 hashes from Debian's packaging. Signed-off-by: "Yann E. MORIN" Cc: Martin Bark Reviewed-by: Samuel Martin Signed-off-by: Peter Korsgaard --- package/ca-certificates/ca-certificates.hash | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 package/ca-certificates/ca-certificates.hash diff --git a/package/ca-certificates/ca-certificates.hash b/package/ca-certificates/ca-certificates.hash new file mode 100644 index 0000000000..bcd0723e51 --- /dev/null +++ b/package/ca-certificates/ca-certificates.hash @@ -0,0 +1,3 @@ +# hashes from: $(CA_CERTIFICATES_SITE)/ca-certificates_$(CA_CERTIFICATES_VERSION).dsc : +sha1 ad57a45f0422fafd78a2e8191e5204f2306cc91b ca-certificates_20140223.tar.xz +sha256 815b7cd97200b0d76450bb3e7d9b65997ac494ab6467b17369f65b2ef94bcb0c ca-certificates_20140223.tar.xz -- 2.30.2