Skip to content
This repository was archived by the owner on Feb 12, 2021. It is now read-only.
This repository was archived by the owner on Feb 12, 2021. It is now read-only.

improve image download verification documentation #583

Open
@mischief

Description

@mischief

documents such as https://coreos.com/os/docs/latest/booting-with-qemu.html instruct a user to download CoreOS images over http. the CoreOS mirrors linked from https://coreos.com/releases/ contain gpg signatures, but our page containing signing key information (https://coreos.com/os/docs/latest/notes-for-distributors.html) and the page that contains the signing key (https://coreos.com/security/image-signing-key/) are not linked from there.

in the past i have tried to troubleshoot problems with users, only to find that their download from the release mirrors (*.release.core-os.net) was corrupted.

all documents that contain directions for downloading images or pages containing direct commands for downloading images should also recommend that a user verify the images.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions