|
|||||||||||
|
verifying archive signature keys?
From: Hadmut Danisch <hadmut(at)danisch.de>
Date: Wed Aug 15 2007 - 04:54:02 EDT
just a question because someone had asked me for help. The problem was that apt-get update had complained about not beeing able to verify signatures due to a missing pgp key.
Was easy to tell to do
but: How would one verify that this key is the correct debian key (and not, e.g. the key used by an intruder to fake packages and simply uploaded to public key repositories)? gpg --check-sigs A70DAF536070D3A1 lists some signatures of several people, but none that I personally know, I don't even know whether these people actually exist. So what's the official way to verify debian archives?
regards
-- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Wed Aug 15 05:47:49 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 07 2007 - 07:52:42 EDT |
||||||||||
|
|||||||||||