Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: debsums: no md5sums for a lot of important packages on sarge

From: Michael Ablassmeier <abi(at)grinser.de>
Date: Mon Oct 08 2007 - 04:08:12 EDT


Alexandros Papadopoulos <apapadop@alumni.cmu.edu> schrieb:
> debsums: no md5sums for ssh

cant reproduce this one. Package ships with md5sums on sarge here.

> So I believe the above output NOT to be the result of a breach. My
> question is, is it acceptable to have so many important and widely
> used packages in *stable* without MD5 checksums?

you cant trust debsums anyway, since the files containing the md5 hashes are not signed.

> Secondly, how can one fix this on a production system? Is the
> following method proposed by Paul Gear @
> http://lists.debian.org/debian-security/2005/06/msg00126.html the
> best/only way?

newer debsum versions support creation of sums for packages which do not ship a md5sum file.

"debsums can generate checksum lists from deb archives for packages that don't  include one."

bye,

  • michael
-- 
To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Mon Oct 8 04:08:56 2007
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:10 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library