Gentoo Archives: gentoo-user

From: "Albert W. Hopkins" <marduk@×××××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Portage + checksums
Date: Tue, 06 Apr 2010 18:24:45
Message-Id: 1270578256.32172.6.camel@necropolis
In Reply to: [gentoo-user] Portage + checksums by "Butterworth
1 On Tue, 2010-04-06 at 14:15 -0400, Butterworth, John W. wrote:
2 > How can I verify that the installed packages on a Gentoo system came
3 > from the same source that was on a main rotation mirror and/or
4 > “blessed” by the Gentoo development team?
5 >
6 >
7 >
8 > By verifying the checksum located in /var/db/pkg/$APPNAME/CONTENTS am
9 > I only confirming that the source was the same as that which was
10 > downloaded from the mirror?
11 >
12 >
13 >
14 > I guess what I’m getting at is how can I be sure I can trust a
15 > mirror?
16 >
17 >
18 >
19 > Thank you very much in advance for any insight provided,
20
21 It really depends on your level of paranoia. Ultimately it can't be
22 trusted at all.
23
24 If you really want to be sure then just the source/manifest from your
25 "trusted" mirror and compare.

Replies

Subject Author
RE: [gentoo-user] Portage + checksums "Butterworth