Gentoo Archives: gentoo-user

From: "Butterworth
To: "gentoo-user@l.g.o" <gentoo-user@l.g.o>
Subject: RE: [gentoo-user] Portage + checksums
Date: Tue, 06 Apr 2010 18:56:45
Message-Id: 8622C222D2FC9D499533B1EEF631D3930332DB4A6F@IMCMBX1.MITRE.ORG
In Reply to: Re: [gentoo-user] Portage + checksums by "Albert W. Hopkins"
1 Thanks.
2
3 Do you know if someone makes a change to a copy of apache hosted on a public mirror, will the sync between the servers determine that it's corrupted (via 'bad' checksum) on the public side and replace it?
4
5 -john
6
7 -----Original Message-----
8 From: Albert W. Hopkins [mailto:marduk@×××××××××××.org]
9 Sent: Tuesday, April 06, 2010 2:24 PM
10 To: gentoo-user@l.g.o
11 Subject: Re: [gentoo-user] Portage + checksums
12
13 On Tue, 2010-04-06 at 14:15 -0400, Butterworth, John W. wrote:
14 > How can I verify that the installed packages on a Gentoo system came
15 > from the same source that was on a main rotation mirror and/or
16 > “blessed” by the Gentoo development team?
17 >
18 >
19 >
20 > By verifying the checksum located in /var/db/pkg/$APPNAME/CONTENTS am
21 > I only confirming that the source was the same as that which was
22 > downloaded from the mirror?
23 >
24 >
25 >
26 > I guess what I’m getting at is how can I be sure I can trust a
27 > mirror?
28 >
29 >
30 >
31 > Thank you very much in advance for any insight provided,
32
33 It really depends on your level of paranoia. Ultimately it can't be
34 trusted at all.
35
36 If you really want to be sure then just the source/manifest from your
37 "trusted" mirror and compare.

Attachments

File name MIME type
smime.p7s application/x-pkcs7-signature

Replies

Subject Author
Re: [gentoo-user] Portage + checksums Jonas de Buhr <jonas.de.buhr@×××.net>
Re: [gentoo-user] Portage + checksums Alan McKinnon <alan.mckinnon@×××××.com>