1 |
Thanks. |
2 |
|
3 |
Do you know if someone makes a change to a copy of apache hosted on a public mirror, will the sync between the servers determine that it's corrupted (via 'bad' checksum) on the public side and replace it? |
4 |
|
5 |
-john |
6 |
|
7 |
-----Original Message----- |
8 |
From: Albert W. Hopkins [mailto:marduk@×××××××××××.org] |
9 |
Sent: Tuesday, April 06, 2010 2:24 PM |
10 |
To: gentoo-user@l.g.o |
11 |
Subject: Re: [gentoo-user] Portage + checksums |
12 |
|
13 |
On Tue, 2010-04-06 at 14:15 -0400, Butterworth, John W. wrote: |
14 |
> How can I verify that the installed packages on a Gentoo system came |
15 |
> from the same source that was on a main rotation mirror and/or |
16 |
> “blessed” by the Gentoo development team? |
17 |
> |
18 |
> |
19 |
> |
20 |
> By verifying the checksum located in /var/db/pkg/$APPNAME/CONTENTS am |
21 |
> I only confirming that the source was the same as that which was |
22 |
> downloaded from the mirror? |
23 |
> |
24 |
> |
25 |
> |
26 |
> I guess what I’m getting at is how can I be sure I can trust a |
27 |
> mirror? |
28 |
> |
29 |
> |
30 |
> |
31 |
> Thank you very much in advance for any insight provided, |
32 |
|
33 |
It really depends on your level of paranoia. Ultimately it can't be |
34 |
trusted at all. |
35 |
|
36 |
If you really want to be sure then just the source/manifest from your |
37 |
"trusted" mirror and compare. |