Should Tails publish a signed copy of their websites public SSL key for download on this website?
My web browser (Tails bundled Iceweasel) can export the public key for tails.boum.org it has received to file
I can also see that the certificate signature algorithm is PKCS #1 SHA-1 With RSA Encryption and the certificate signature value is:
Size: 256 Bytes / 2048 Bits
01 e1 ab 29 75 61 0e c9 c7 4b fb 7f bd 02 91 2d
3a db 7d 47 f8 82 f7 27 36 1e 02 f1 82 9f f5 3c
03 54 8e 3e bf e0 ec a5 27 47 f0 e2 bd 86 1c 24
70 50 0f 48 40 6b dd bf b0 25 63 1d e1 f2 7e bf
37 6a b3 6e f7 6a c5 11 f4 fc e3 65 a4 d4 63 f3
f3 9a 43 03 3b 1f fd d1 8a 90 e5 16 c4 a8 cd 97
c5 c2 e5 83 8e 93 4a 80 84 10 df af 75 3f 77 07
8b d4 69 f3 4c 85 52 a8 8d 68 11 b6 c9 3d 0f 3e
9e 12 3c 59 b8 93 e4 d3 d1 f6 f1 65 d7 5d d1 53
37 6a a9 09 cd 06 33 47 5f 2a e0 76 61 c5 b9 c7
87 0a 9f b7 52 8b 66 96 2d ac 3c 04 1f 4a 59 88
57 a4 32 c9 e6 54 d3 f2 ad 54 a3 21 f1 2d d1 c2
56 75 37 b8 31 05 12 ce 9f ca 11 5f 82 2b 41 4b
d5 9d 75 31 70 a1 c3 f9 43 e7 32 de 3d fc f4 b3
1f df 3c 5b 1b d9 c9 b3 7a d1 29 63 b9 41 16 6b
9e ed 7f 43 12 34 1e 2f 35 2f af 49 f6 ad 73 d5
This is for a certificate that GANDI SAS says is valid for *.boum.org
SSL keys dont change much, it is very infrequent.
If tails publishes for download a signed copy (signed with the same key used to sign tails .isos) of the hash of their SSL public key, then GANDI SAS can get compromised all they want, co-opted by the government, hacked whatever. I'll already know what the hash of the *.boum.org certificate should be
Please discuss
[[wishlist]]