Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-25687

Provide sha256 checksums for downloads and Sign Windows installer package

    • 5
    • 14
    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      NOTE: This suggestion is for Confluence Server. Using Confluence Cloud? See the corresponding suggestion.

      We should add sha256 checksums for Confluence downloads and the Windows installer should have the certificate used to sign it updated as it is expired.

            [CONFSERVER-25687] Provide sha256 checksums for downloads and Sign Windows installer package

            +1

            https://getsupport.atlassian.com/browse/GHS-179655 Another request from Jira customer

            Kiran Srinivas (Inactive) added a comment - https://getsupport.atlassian.com/browse/GHS-179655  Another request from Jira customer

            We are also getting pushback from our security on this issue on all of our instances. Please incorporate this feature. 

            Best,

            Amanda

            Amanda Morton added a comment - We are also getting pushback from our security on this issue on all of our instances. Please incorporate this feature.  Best, Amanda

            Atlassian,

            We are being chased by security on this. Any update is appreciated.

             

            Cheers,

            Gaj

            Gaj Umapathy added a comment - Atlassian, We are being chased by security on this. Any update is appreciated.   Cheers, Gaj

            Funet CERT added a comment -

            It is standard procedure to review checksums of any downloads before you install and use it. But as there is no checksums available you should not download or test these possible malisious products. There is none good reason not to provide the prove of authenticity. And even you might trust the Atlassian's end the downloaded package could get exploited or got br0ken in transit. This is not the way you should provide binaries for you customers. So sad.

            Funet CERT added a comment - It is standard procedure to review checksums of any downloads before you install and use it. But as there is no checksums available you should not download or test these possible malisious products. There is none good reason not to provide the prove of authenticity. And even you might trust the Atlassian's end the downloaded package could get exploited or got br0ken in transit. This is not the way you should provide binaries for you customers. So sad.

            GÉANT IT added a comment - - edited

            Hi I just noticed that the issue title has been changed so that it narrows down to "Sign Windows installer package" (not sure what that exactly means btw).
            Please change it back as the issue does apply to ALL downloads.

            THanks!

            GÉANT IT added a comment - - edited Hi I just noticed that the issue title has been changed so that it narrows down to "Sign Windows installer package" (not sure what that exactly means btw). Please change it back as the issue does apply to ALL downloads. THanks!

            Hi all, just a quick update, this is something which we intend to address in the near future. Keep Watching for updates.

             

            Adam Barnes (Inactive) added a comment - Hi all, just a quick update, this is something which we intend to address in the near future. Keep Watching for updates.  

            100% agree with Stefan. 

             
            Dear Atlassians, can you please stop ignoring your paying customers and provide cryptographically signed downloads?
             

            Matjaž Antloga - BalkanCloud IT added a comment - 100% agree with Stefan.    Dear Atlassians, can you please stop ignoring your paying customers and  provide cryptographically signed downloads ?  

            Stefan added a comment -

            This issue is 5 years old.

            It seems no one is working on this. Does this issue get any attention from your side?

            Dear Atlassians, can you please stop ignoring your paying customers and provide cryptographically signed downloads?

            Stefan added a comment - This issue is 5 years old . It seems no one is working on this. Does this issue get any attention from your side? Dear Atlassians, can you please stop ignoring your paying customers and provide cryptographically signed downloads ?

            Wow, why no signed packages, or checksums at least?  Furthermore, I was hit by a double compression issue when downloading, with JIra and bitbucket.  Can you please fix your webserver?

             

            "Meaning, if you downloaded this from a web server, sometimes Gzip compression get’s applied to web content on the server level to speed up content download. But if not properly set on the server to ignore already compressed content such as this, it can inadvertently double-Gzip files."

            https://superuser.com/questions/841865/extracting-a-tar-gz-file-returns-this-does-not-look-like-a-tar-archive

            Vendor Support added a comment - Wow, why no signed packages, or checksums at least?  Furthermore, I was hit by a double compression issue when downloading, with JIra and bitbucket.  Can you please fix your webserver?   " Meaning, if you downloaded this from a web server, sometimes Gzip compression get’s applied to web content on the server level to speed up content download. But if not properly set on the server to ignore already compressed content such as this, it can inadvertently double-Gzip files. " https://superuser.com/questions/841865/extracting-a-tar-gz-file-returns-this-does-not-look-like-a-tar-archive

              Unassigned Unassigned
              aconde Alejandro Conde Carrillo (Inactive)
              Votes:
              81 Vote for this issue
              Watchers:
              61 Start watching this issue

                Created:
                Updated: