Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

verifying archive signature keys?

From: Hadmut Danisch <hadmut(at)danisch.de>
Date: Wed Aug 15 2007 - 04:54:02 EDT


Hi,

just a question because someone had asked me for help. The problem was that apt-get update had complained about not beeing able to verify signatures due to a missing pgp key.

Was easy to tell to do
gpg --recv-key A70DAF536070D3A1
gpg -a --export A70DAF536070D3A1 | sudo apt-key add -

but: How would one verify that this key is the correct debian key (and not, e.g. the key used by an intruder to fake packages and simply uploaded to public key repositories)?

gpg --check-sigs A70DAF536070D3A1

lists some signatures of several people, but none that I personally know, I don't even know whether these people actually exist.

So what's the official way to verify debian archives?

regards
Hadmut

-- 
To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Wed Aug 15 05:47:49 2007
Do you need help?X

This archive was generated by hypermail 2.1.8 : Sun Oct 07 2007 - 07:52:42 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library