View Issue Details
|ID||Project||Category||View Status||Date Submitted||Last Update|
|0001855||Kali Linux||General Bug||public||2014-11-02 15:59||2014-12-04 15:28|
|Priority||normal||Severity||minor||Reproducibility||have not tried|
|Summary||0001855: There are two versions of kali-linux-1.0.9a-amd64.iso, both with signed SHA1SUMS|
Depending on a mirror, one can get two different versions of kali-linux-1.0.9a-amd64.iso. One of them has sha1sum as seen on webpage (2744d50f56c3d6332bc75e676f36aad3058d0aad) the other one has different (0fd0cbaedc0daa7a9af5d3e76f9991bba5b0e3bd). The different one can be obtained e.g. from http://kali.solaraservers.com/kali-images/kali-1.0.9a/) There are also two different versions of SHA1SUMS file and even two versions of SHA1SUMS.gpg (for each iso). The interesting thing is that both of these signatures verify with the same kali key (44C6 513A 8E4F B3D3 0875 F758 ED44 4FF0 7D8D 0BF6).
|Steps To Reproduce|
Download kali iso, sha1sums and sha1sums.gpg from this mirror: http://kali.solaraservers.com/kali-images/kali-1.0.9a/ and also from some other mirror. Observe that files differ, but SHA1SUMS are both signed with Kali key.
stevko@napo ~/tmp$ find
For now, I dropped kali.solaraservers.com from the mirror list. But I'll implement an out-of-sync check like we already have for the two other repositories... with a longer delay since it changes less often and is not SSH triggered.
FWIW the 1.0.9a ISOs have been generated multiple times due to problems found after the generation and looks like this mirror mirrored the bad images once and never caught up since...
I have now extended my monitoring script to also cover kali-images mirror. Any mirror that has not synced in the last two days will be dropped from the mirror rotation.
|2014-11-02 15:59||stevko||New Issue|
|2014-11-03 08:30||rhertzog||Note Added: 0002681|
|2014-11-03 08:30||rhertzog||Assigned To||=> rhertzog|
|2014-11-03 08:30||rhertzog||Status||new => assigned|
|2014-11-03 08:31||rhertzog||Note Added: 0002682|
||Issue cloned: 0001895|
|2014-12-04 15:28||rhertzog||Note Added: 0002854|
|2014-12-04 15:28||rhertzog||Status||assigned => resolved|
|2014-12-04 15:28||rhertzog||Resolution||open => fixed|