Skip to content

Request: Please cryptographically sign osTicket releases with gpg #5750

@maltfield

Description

@maltfield

Description

Currently it is not possible to verify the authenticity or cryptographic integrity of the downoads from osticket.com or github.com because the releases are not cryptographically signed.

This makes it hard for osTicket customers to safely obtain the osTicket software, and it introduces them (and potentially their customer's data) to watering hole attacks.

Steps to Reproduce

  1. Go to the osticket.com/download page
  2. Click download
  3. ???

Expected behavior: [What you expected to happen]

A few things are expected:

  1. I should be able to download the osTicket PGP key out-of-band from popular third-party keyservers (eg https://keys.openpgp.org/)
  2. I should be able to download a cryptographic signature of the release (or, better, the releases' digest file, such as a SHA256SUMS.asc file) along with the release itself
  3. The downloads page itself should include a link to the documentation page that describes how to do the above two steps

Actual behavior: [What actually happened]

There's just literally no information on verifying downloads, and it appears that it is not possible to do so.

Versions

Everything, all versions. Plugins too.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions