Actually MD5 is nice just for verifying that your download wasn't corrupted. Not everyone uses PGP/GPG....

-- Sean

David M Johnson wrote:

On May 10, 2006, at 11:50 AM, Noel J. Bergman wrote:

1) If it'll be an ASF release, then it needs to get PGP (gpg is the
better tool btw) signed.

Should be, yes.  Easy to do.  Quite trivial, in fact.  I would not bother
with MD5 if you've signed it.

If you need help, I can provide a shell script with commends to do the
signing.

Yes please. - Dave




Reply via email to