Akira25 / autoupdate

Draft of an autoupdater for Freifunk Berlin. Deprecated in favour of rewrite. https://github.com/freifunk-berlin/falter-packages/tree/master/packages/falter-berlin-autoupdate
2 stars 0 forks source link

[Security] check firmware-image for authenticy #8

Open Akira25 opened 4 years ago

Akira25 commented 4 years ago

The firmware file should be checked for authenticy. This could be accomplished by checking the sha256sum of the file against a checksum delivered with the (signed) link definition file. This also implies changes in the generation of those lists in json-creator.

Akira25 commented 4 years ago

This issue is currently blocked by freifunk-berlin/buildbot/issues/61