Feature #12630

Feature #5630: Reproducible builds

Document how users can verify a reproducibly built ISO/IUK

Added by u 20 days ago. Updated about 17 hours ago.

Status:In ProgressStart date:06/02/2017
Priority:NormalDue date:
Assignee:anonym% Done:

0%

Category:-
Target version:-
QA Check:Ready for QA Blueprint:
Feature Branch:451f:tailsfeature/12630+reproducible_build_verify Easy:
Type of work:Contributors documentation Affected tool:

Related issues

Related to Tails - Feature #12626: Design doc for reproducible builds Confirmed 05/31/2017

History

#1 Updated by u 20 days ago

  • Assignee set to u

Notes

- download our .sig and verify it against your own build
- when someone reproducibly builds our .iso they have a file that is exactly the same as ours, which the .sig will verify for them
- there's a way to extract the SHA from the .sig.
- the SHAAA is already in IDFs and UDFs

#2 Updated by intrigeri 20 days ago

- download our .sig and verify it against your own build

This won't work for IUKs though, but their SHA is available in our UDFs.

#3 Updated by u about 17 hours ago

  • Feature Branch set to 451f:tailsfeature/12630+reproducible_build_verify

#4 Updated by u about 17 hours ago

  • Status changed from Confirmed to In Progress

#5 Updated by u about 17 hours ago

  • Assignee changed from u to intrigeri
  • QA Check set to Ready for QA

I added a page about this and would love someone from the foundations team to verify what I wrote and improve on it. Tentatively assigning to intrigeri.

  • I don't know how to verify an IUK so this part is missing
  • Is there an archive of our OpenPGP signatures so that people can verify older builds in the future?
  • Is there an archive of our IDFs/SHAsums so that people can verify older builds in the future?

You can also reassign this to me if you think there is too much information missing.

#6 Updated by u about 17 hours ago

#7 Updated by u about 17 hours ago

  • Assignee changed from intrigeri to anonym

Actually, as anonym is supposed to write the design doc, this might be more suitable to have a review from him instead.

Also available in: Atom PDF