I think I actually got the right file. The size of the original file should?? How do you justify the blanket statement "It is much better to use digital signature instead of md5sum to protect the integrity of the file." ??
be 4,370,640,896. Previously I used Internet Explorer to see the file size
in the file property. Clearly it gives a wrong number. But still we
implicitely assume all mirrors sites are trustable and are properly
protected. It is much better to use digital signature instead of md5sum to
protect the integrity of the file.
----- Original Message ----- From: "Xinming He" <xhe usc edu>
To: <fedora-list redhat com>
Sent: Tuesday, May 25, 2004 7:16 PM
Subject: problem with FC2-i386-DVD.iso
I downloaded FC2-i386-DVD.iso from a mirror site ftp://limestone.uoregon.edu/fedora/ using Internet Explorer. It is strange to see that the size of the file I got is 4,370,640,896, while the size of the original file is 4,294,967,295. I got the same md5sum as specified in the redhat web site. It is quite strange. Not sure if I have got the right file. It would be better if the file is protected with some digital signature instead of the simple md5sum.