Ed Flecko <> wrote:
> I'd like to be able to confirm that a downloaded patch from Microsoft
> has not been altered.
All Microsoft downloads are Digitally Signed, complete with an in-built
checksum hash, and verified by a security certificate.
Right click on the downloaded file, select "Properties".
Click tab "Digital Signatures".
Select the first or only signature listed, and click "Details".
The checksum hash (sha1) will be verified, and the certificate checked.
If you see the message "This digital signature is OK", then you can be
confident that the file is exactly as sent by Microsoft.
There is no need for any secondary external list of MD5 hashes, etc., of the
sort you were asking for.
--
Robin Walker [MVP Networking]