1 |
Hi! |
2 |
|
3 |
On Mon, 08 Nov 2004, Kurt Lieber wrote: |
4 |
> > The entire contents of /usr/portage is not authenticated. |
5 |
> > All the manifest files, all the patches, all the ebuilds are |
6 |
> > obtained through a public network without _any_ form of |
7 |
> > authentication. |
8 |
> |
9 |
> That is factually incorrect. |
10 |
> |
11 |
> Pick any Gentoo machine that has a reasonably recent portage tree and do |
12 |
> any of the following: |
13 |
> |
14 |
> cat /usr/portage/sys-apps/portage/Manifest |
15 |
|
16 |
This does not contain a GPG signature here. Of all packages... |
17 |
|
18 |
> cat /usr/portage/app-editors/vim/Manifest |
19 |
> cat /usr/portage/dev-lang/perl/Manifest |
20 |
|
21 |
I've run a script across the entire tree, collecting 43 different |
22 |
signature keys IDs from Manifest files in all (from a total of |
23 |
2074 signed Manifest files, making up about 1/4). Of those keys, |
24 |
16 were unavailable on the Subkeys Public Key Network (listed |
25 |
below). Where can I get those? |
26 |
|
27 |
0x012E7061 |
28 |
0x1E37DA76 |
29 |
0x2D86E6F4 |
30 |
0x3526BFED |
31 |
0x8256272E |
32 |
0x8F01B50A |
33 |
0x96E7B687 |
34 |
0xAD8D10B6 |
35 |
0xAF09E289 |
36 |
0xB0FAE1C1 |
37 |
0xBC58B271 |
38 |
0xC4BBD87A |
39 |
0xCA9EC979 |
40 |
0xE95F7581 |
41 |
0xEB0E2EF7 |
42 |
|
43 |
Wondering, |
44 |
Tobias |
45 |
-- |
46 |
export DISPLAY=vt100 |
47 |
|
48 |
-- |
49 |
gentoo-security@g.o mailing list |