Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

Any way to download Reader from a secure/authenticated source?

New Here ,
Oct 22, 2014 Oct 22, 2014

All links I can find result in a plain-HTTP download, which can be undetectably tampered with in transit.

Even changing the plain HTTP Adobe - Adobe Reader download - All versions to HTTPS Adobe - Adobe Reader download - All versions still results in a plain-HTTP download.

The @Deleted User twitter account suggested secure FTP to ftp.adobe.com, but SFTP doesn't provide source-server authentication (nor does ftp.adobe.com even seem to answering SFTP).

Publishing the official secure checksums of the installers via a secure authenticated channel would also be good, but I couldn't find those anywhere, either. A Google search for the actual SHA1 of the executable I received (54fd10c7d36895469f6bfb1cd01ec04a633f8c5d for 'AdobeReaderInstaller_11_en_ltrosxd_aaa_aih.dmg') had no hits, suggesting official checksums haven't been prominently announced.

Adobe's auto-update mechanisms must be secured by crypto against tampering in transit, right? So why isn't the initial download?

Any pointers appreciated.

- Gordon

1.0K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines

correct answers 1 Correct answer

Adobe Employee , Oct 24, 2014 Oct 24, 2014

This is the download from Adobe's download center which involve Adobe's download manager downloading the bits. One you mount the dmg, you can verify using the codesign tool:

$ codesign -vvv /Volumes/Adobe\ Reader\ Installer/Install\ Adobe\ Reader.app

You can also download complete Mac installers (sans the download manager) from:

ftp://ftp.adobe.com/pub/adobe/reader/mac/11.x/11.0.09/en_US/AdbeRdr11009_en_US.dmg (full installer)

ftp://ftp.adobe.com/pub/adobe/reader/mac/11.x/11.0.09/misc/AdbeRdrUpd11009.pkg

...
Translate
Adobe Employee ,
Oct 23, 2014 Oct 23, 2014

All downloads are digitally signed. Would verifying the signature achieve your objective?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 24, 2014 Oct 24, 2014

Yes, verifying an Adobe signature of the download would assure me it's authentic.

How can I verify the signature of 'AdobeReaderInstaller_11_en_ltrosxd_aaa_aih.dmg'? Is the signature embedded in the download itself?

- Gordon

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 24, 2014 Oct 24, 2014

This is the download from Adobe's download center which involve Adobe's download manager downloading the bits. One you mount the dmg, you can verify using the codesign tool:

$ codesign -vvv /Volumes/Adobe\ Reader\ Installer/Install\ Adobe\ Reader.app

You can also download complete Mac installers (sans the download manager) from:

ftp://ftp.adobe.com/pub/adobe/reader/mac/11.x/11.0.09/en_US/AdbeRdr11009_en_US.dmg (full installer)

ftp://ftp.adobe.com/pub/adobe/reader/mac/11.x/11.0.09/misc/AdbeRdrUpd11009.pkg (updater pkg)


For the PKG extracted from the full 11.0.9 installer DMG

$ pkgutil --check-signature Adobe\ Reader\ XI\ Installer.pkg

For the update PKG:

pkgutil --check-signature AdbeRdrUpd11009.pkg

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Oct 27, 2014 Oct 27, 2014

I still get error 1311 when installing Adobe reader for PC

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Oct 28, 2014 Oct 28, 2014
LATEST

Chuck Lynn, I'm not sure I see the connection to this discussion? Or any earlier message to go back to? Is this actually a brand new problem?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines