Gentoo Archives: gentoo-security

From: Tobias Klausmann <klausman@××××××××××××.de>
To: gentoo-security@l.g.o
Cc: Peter Simons <simons@××××.to>
Subject: Re: [gentoo-security] Re: No, apparently not. (was: Is anybody else worried about this?)
Date: Mon, 08 Nov 2004 09:19:50
Message-Id: 20041108091926.GA4342@eric.schwarzvogel.de
In Reply to: Re: [gentoo-security] Re: No, apparently not. (was: Is anybody else worried about this?) by Kurt Lieber
1 Hi!
2
3 On Mon, 08 Nov 2004, Kurt Lieber wrote:
4 > > The entire contents of /usr/portage is not authenticated.
5 > > All the manifest files, all the patches, all the ebuilds are
6 > > obtained through a public network without _any_ form of
7 > > authentication.
8 >
9 > That is factually incorrect.
10 >
11 > Pick any Gentoo machine that has a reasonably recent portage tree and do
12 > any of the following:
13 >
14 > cat /usr/portage/sys-apps/portage/Manifest
15
16 This does not contain a GPG signature here. Of all packages...
17
18 > cat /usr/portage/app-editors/vim/Manifest
19 > cat /usr/portage/dev-lang/perl/Manifest
20
21 I've run a script across the entire tree, collecting 43 different
22 signature keys IDs from Manifest files in all (from a total of
23 2074 signed Manifest files, making up about 1/4). Of those keys,
24 16 were unavailable on the Subkeys Public Key Network (listed
25 below). Where can I get those?
26
27 0x012E7061
28 0x1E37DA76
29 0x2D86E6F4
30 0x3526BFED
31 0x8256272E
32 0x8F01B50A
33 0x96E7B687
34 0xAD8D10B6
35 0xAF09E289
36 0xB0FAE1C1
37 0xBC58B271
38 0xC4BBD87A
39 0xCA9EC979
40 0xE95F7581
41 0xEB0E2EF7
42
43 Wondering,
44 Tobias
45 --
46 export DISPLAY=vt100
47
48 --
49 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Re: No, apparently not. (was: Is anybody else worried about this?) Kurt Lieber <klieber@g.o>
Re: [gentoo-security] Re: No, apparently not. Thierry Carrez <koon@g.o>
[gentoo-security] Keys on a cd? Anthony Metcalf <anthony.metcalf@×××××××××××.cx>