Verify the Integrity of your Software Download V4.7 Build 014 - With IT Libraries

TYPE FILENAME FILE SIZE
Windows Install SecurITree-setup.exe 35,720,376 bytes
UNIX/Linux Install SecurITree.tgz 28,759,233 bytes
Mac OS X Install SecurITree.zip 29,905,658 bytes

The integrity of Amenaza's SecurITree program can be confirmed in three ways. The first method uses the SHA-1 algorithm specified by NIST in FIPS 180-1 to compute a cryptographic hash or message digest of downloaded files.

SHA-1 Checksums:

TYPE FILENAME SHA-1 CHECKSUM
Windows Install SecurITree-setup.exe 68aa87be6231c41c541f6372929a1a6f7d44e77b
UNIX/Linux Install SecurITree.tgz 3b98feee54e469711494a8736a5c606978c2bad7
Mac OS X Install SecurITree.zip 286cc2cb7efdf414435cac8b3a6ef76987023223

Programs to compute and verify SHA-1 hashes are widely available. This makes it convenient for verifying that tampering of files has not occurred.

SHA-256 Checksums:

TYPE FILENAME SHA-256 CHECKSUM
Windows Install SecurITree-setup.exe d58e06b43e8b07c37ebfe0392a39085792d033db2008d30c92befbd65caabf56
UNIX/Linux Install SecurITree.tgz e8d7dc47bc526ce8f0be1d565fda97870a2370395b233076342bfbab3b4b9c79
Mac OS X Install SecurITree.zip 50f4eac76fc77d652983fb3d7e6779dba5b4ad8858b57ecabd1a50004bcca1a2

These methods are not a 100% guarantee of integrity. If Amenaza's web server has been compromised it is possible that the intruder may have introduced viruses, worms, Trojan Horses or other malware into the downloadable files and then posted matching SHA-1 message digests on the website! The next integrity verification mechanism described below is a stronger guarantee of file integrity and should be used if SecurITree will be used in a sensitive environment or if there is any suspicion that the downloaded code has been compromised.

The downloadable files have been digitally signed using Pretty Good Privacy (PGP) software and/or GNU Privacy Guard. This software is available commercially from http://www.pgp.com or as freeware from http://www.gnupg.org.

PGP Signature Files:

TYPE FILENAME PGP SIGNATURE FILES
Java Executable SecurITree.jar SecurITree.jar.asc
Windows Install SecurITree-setup.exe SecurITree-setup.exe.asc
UNIX/Linux Install SecurITree.tgz SecurITree.tgz.asc
Mac OS X Install SecurITree.zip SecurITree.zip.asc

The public half of the Amenaza Software signing key pair can be obtained from the PGP keyserver (http://keyserver.pgp.com) using the PGP Key Management utility. Search for "Amenaza Technologies Limited Software Signing Key" or "support@amenaza.com". Note that this site cannot be queried using the LDAP utility built into most browsers.

Since the private half of the Amenaza Software signing key pair used to sign the files is not stored on the Amenaza web server it is NOT possible for an intruder to create a valid signature file even if they compromise the web server. It is, however, possible that the PGP key server may have had the Amenaza Software signing key replaced by a rogue key.

If you are operating in a sensitive environment we recommend that you contact Amenaza Technologies at 1-888-949-9797 (1-403-263-7737) to verify the signing key fingerprint in an 'Out of Band' manner.

Amenaza Software Signing Key Fingerprint:

AE31 1695 86F5 BF87 0384 5314 D4F9 ABC2 D654 5B79

OR

robust company backward Montana
necklace visitor slingshot liberty
acme Jupiter dwelling belowground
steamship Waterloo rhythm repellent
stockman equation erase inertia