l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
January 6: Social gathering
Next Installfest:
TBD
Latest News:
Nov. 18: Club officer elections
Page last updated:
2002 Oct 06 11:38

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] possible rooted system / checking md5sum on debian
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] possible rooted system / checking md5sum on debian



Not a direct answer to your Q, but related.

After installation of packages, AIDE or tripwire can help to check for
file mods with md5 This does nothing for checking the package before you
install it though. :-(

I dont know of a system to check for MD5 sums of all debain packages and
verify. There have been discussions about how to have cert signing of
packages, but who would be a central authority to sign packages? GPG
might allow for a decentralized, distributed signing system, but it has
drawbacks too. :-(

In some ways, MD5 is not as secure as gpg signed packages, but imagine
the keyring!

Sorry I dont have an answer for you, but I would like to see what other
people say.

-ME

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/CM$/IT$/LS$/S/O$ !d--(++) !s !a+++(-----) C++$(++++) U++++$(+$) P+$>+++ 
L+++$(++) E W+++$(+) N+ o K w+$>++>+++ O-@ M+$ V-$>- !PS !PE Y+ PGP++
t@-(++) 5+@ X@ R- tv- b++ DI+++ D+ G--@ e+>++>++++ h(++)>+ r*>? z?
------END GEEK CODE BLOCK------
decode: http://www.ebb.org/ungeek/ about: http://www.geekcode.com/geek.html

On Sun, Oct 06, 2002 at 10:14:41AM -0700, Peter Jay Salzman wrote:
> is there any automated way to check md5sums of all packages that provide
> binaries for debian packages?
> 
> someone mentioned that there was talk about this as a new feature for
> apt-get.
> 
> i _really_ don't want satan to be rooted.
> 
> pete
> 
> ----- Forwarded message from paolo <paolo@xcf.berkeley.edu> -----
> 
> Date: Sat, 5 Oct 2002 21:34:20 -0700 (PDT)
> From: paolo <paolo@xcf.berkeley.edu>
> To: Peter Jay Salzman <p@dirac.org>
> Cc: <linux@csua.berkeley.edu>
> Subject: Re: debian archive
> 
> it was rooted.
> i would md5 your binaries to make sure you're ok.
> (i'm in the process of doing same)
> 
> On Sat, 5 Oct 2002, Peter Jay Salzman wrote:
> 
> > hi there,
> >
> > you're my favorite debian mirror, but linux.csua.berkeley.edu seems
to
> > not be responding to apt-get update for the past few days.
> >
> > has the mirror been taken down?  are you having server troubles?
> >
> > thanks!
> > pete
> >
> >
> 
> 
> ----- End forwarded message -----
> 
> -- 
> Fingerprint: B9F1 6CF3 47C4 7CD8 D33E 70A9 A3B9 1945 67EA 951D
> _______________________________________________
> vox-tech mailing list
> vox-tech@lists.lugod.org
> http://lists.lugod.org/mailman/listinfo/vox-tech

-- 
-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/CM$/IT$/LS$/S/O$ !d--(++) !s !a+++(-----) C++$(++++) U++++$(+$) P+$>+++ 
L+++$(++) E W+++$(+) N+ o K w+$>++>+++ O-@ M+$ V-$>- !PS !PE Y+ PGP++
t@-(++) 5+@ X@ R- tv- b++ DI+++ D+ G--@ e+>++>++++ h(++)>+ r*>? z?
------END GEEK CODE BLOCK------
decode: http://www.ebb.org/ungeek/ about: http://www.geekcode.com/geek.html
  Campus IT(/OS Security): Operating Systems Support Specialist Assistant
_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Appahost Applications
For a significant contribution towards our projector, and a generous donation to allow us to continue meeting at the Davis Library.