Page 1 of 1

Verification of the SHA256SUMS file

Posted: 20. Apr 2016, 14:06
by ergo
Helo,

hopefully this is the right board for my question.

When I have downloaded Virtualbox Install file and VB-Extensions file I have run the checksum control. The checksums matched. But how do I check that SHA256SUMS file isn’t compromised itself?

I got the public key by downloading oracle_vbox.asc.

gpg —verify SHA256SUMS doesn’t work as it does for *.asc files.

Now what is the correct terminal command for OS X or Debian Linux systems to verify SHA256SUMS itself?

Thank you in advance.

Re: Verification of the SHA256SUMS file

Posted: 20. Apr 2016, 16:47
by mpack
The checksum is a check for detecting accidental corruption, it is not a security feature. Security comes from embedded certificates, not checksums.

We already had this discussion quite recently. Please read: viewtopic.php?f=9&t=76599.