1 |
On Tue, 2010-04-06 at 14:15 -0400, Butterworth, John W. wrote: |
2 |
> How can I verify that the installed packages on a Gentoo system came |
3 |
> from the same source that was on a main rotation mirror and/or |
4 |
> “blessed” by the Gentoo development team? |
5 |
> |
6 |
> |
7 |
> |
8 |
> By verifying the checksum located in /var/db/pkg/$APPNAME/CONTENTS am |
9 |
> I only confirming that the source was the same as that which was |
10 |
> downloaded from the mirror? |
11 |
> |
12 |
> |
13 |
> |
14 |
> I guess what I’m getting at is how can I be sure I can trust a |
15 |
> mirror? |
16 |
> |
17 |
> |
18 |
> |
19 |
> Thank you very much in advance for any insight provided, |
20 |
|
21 |
It really depends on your level of paranoia. Ultimately it can't be |
22 |
trusted at all. |
23 |
|
24 |
If you really want to be sure then just the source/manifest from your |
25 |
"trusted" mirror and compare. |