home bbs files messages ]

Forums before death by AOL, social media and spammers... "We can't have nice things"

   comp.mobile.android      Discussion about Android-based devices      236,147 messages   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]

   Message 235,896 of 236,147   
   Maria Sophia to Maria Sophia   
   Re: FOSS Contacts app with privacy for b   
   12 Feb 26 18:27:13   
   
   From: mariasophia@comprehension.com   
      
   Maria Sophia wrote:   
   >  Subject: C=US,O=Android,CN=Android Debug   
   >  Issuer: C=US,O=Android,CN=Android Debug   
      
   Ooops. I was trying to be helpful to Martin, as I'm one of the most helpful   
   people on this newsgroup, but I accidentally opened the "gitlab debug" APK.   
      
   This is the certificate for the F-Droid APK.   
   Note that the APK doesn't need to be installed.   
   It simply needs to exist.   
      
   Note this is signed by the F-Droid team & is NOT a debug version.   
      
   Serial Number: 0x7bb18041   
   Type: X.509   
   Version: 3   
   Serial Number: 0x7bb18041   
      
   Subject: CN=FDroid, OU=FDroid, O=fdroid.org, L=ORG, ST=ORG, C=UK   
      
   Valid from: Oct 27, 2018 11:56 AM   
   Valid until: Mar 14, 2046 10:56 AM   
      
   Signature   
   Algorithm: SHA256withRSA   
   OID: 1.2.840.113549.1.1.11   
      
   Public Key   
   Algorithm: RSA (2048 bits)   
   Exponent: 65537   
   Modules: 1971285407099715896945847078550604694311727126397587507   
   7381275334308114048623171374897213578246020462451164391419433821   
   2966192713558982437347399065914485986653990945550850054727022879   
   422007759808679021149619966058644212179996730293688331909535   
   4123886406063504730570852437652937129672759007668740332355344727   
   7992159776190173636940392359245680924453102920453841341807591950   
   0963472573757145594669500045894328352244000976604246820946728266   
   730284374527122058953776138060961564466738216007745335037825   
   9487431636122498627937505421745073400858988827614389804992924005   
   018380539356526298057098572766426945143487600077317   
      
   CRC32: 03366234   
   MD5: 7ba54b67b1a2cea0396ab533ae731807   
   SHA1: efa927efe8218e143bf8ef5e8d8c33d7dbda5792   
   SHA256: b9ab2d7861cd40b98ca41a1fe0aa220d53135829ffeaf6b6c64b3b36b2df9505   
   SHA384: b8469130a823813560b5e404ed024e8d3ffd3b96400856d67c6a537e   
   0f03cefcba0e14535e4a9eb43ec38d3367304a3   
   SHA512: 107121542beb30e84208790edd234d981127113511e6f5b1a846ebad   
   71eac7b3dfbe19d933faa4d804b0a07ac9a845d83dd53b9271f4914012482faef43c48b   
      
   What specifically matters for this issue Martin is expressing is:   
    Subject: CN=FDroid, OU=FDroid, O=fdroid.org, L=ORG, ST=ORG, C=UK   
    Algorithm: SHA256withRSA   
    Public Key: RSA (2048 bits)   
    SHA256 fingerprint of the certificate   
   The question for Martin is what he sees if he doesn't see that?   
      
   What else matters is the SHA‑256 fingerprint of the certificate.   
   Because that is the true identity of the signing key.   
      
   Note that this is the certificate's SHA-256 fingerprint:   
   SHA-256: b9ab2d7861cd40b98ca41a1fe0aa220d53135829ffeaf6b6c64b3b36b2df9505   
   This is the true identity of the signing key.   
   If the installed version has a different SHA-256 fingerprint   
   then Android rejects the update.   
      
   That one line is the #1 value that determines compatibility   
   where the #2 line that determines compatibility is the modulus.   
   Modulus: 009c27e7fecd6c93a46d92ddd5e1f4912ff68644f8e97f1b718163f   
   37c48c1c6f41f4a97...   
   If the public key modulus doesn't match, then Android rejects it too.   
      
   In summary, since I'm one of the most helpful people on this ng,   
   I will summarize for Martin that the most important things are   
   1. Subject   
      CN=FDroid, OU=FDroid, O=fdroid.org...   
   2. Certificate SHA-256 fingerprint   
      b9ab2d7861cd40b98ca41a1fe0aa220d53135829ffeaf6b6c64b3b36b2df9505   
   3. Public key modulus   
      009c27e7fecd6c93a46d92ddd5e1f4912ff68644f8e97f1b718163f237c48c1...   
   All of which is available to anyone who has the APK in hand.   
   --   
   To install apps doesn't take much effort but to debug when an app   
   doesn't install takes enough knowledge to solve what comes up at us.   
      
   --- SoupGate-Win32 v1.05   
    * Origin: you cannot sedate... all the things you hate (1:229/2)   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]


(c) 1994,  bbs@darkrealms.ca