drduh / macOS-Security-and-Privacy-Guide

Guide to securing and improving privacy on macOS

Home Page:https://drduh.github.io/macOS-Security-and-Privacy-Guide/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Update on section 'Verify installation integrity'

opened this issue · comments

Not that it is of such importance, but if possible, please update the section "Verify installation integrity".

Note that as mentioned almost a year ago, Apple has updated certificates validation.

Published Date: November 03, 2019

TLS server certificates and issuing CAs using RSA keys must use key sizes greater than or equal to 2048 bits. Certificates using RSA key sizes smaller than 2048 bits are no longer trusted for TLS.

SHA-1 signed certificates are no longer trusted for TLS, thus that example is no longer adequate.

commented

The command likely outputs SHA-256 signatures now. Can anyone with access to it and the macOS installer app confirm?