|
|||||||||||
|
Re: Manipulated squirrelmail download archives - how to detect such cases automatically in the Debian packaging process?
From: Javier Fernández-Sanguino Peña <jfs(at)computer.org>
Date: Tue Dec 25 2007 - 14:26:44 EST
No, there's nothing in the archive. It's up to the maintainers to (manually) verify this. > Would it make sense to add something to the packaging infrastructure or I'm not sure that process could be easily automated. You might want to read the Strong Distribution HOWTO available at http://www.cryptnet.net/fdp/crypto/strong_distro.html to see some of the issues at hand. A possible extension to the information sent to ftp-master.debian.org (*not* ftp.debian.org since that is a mirror and not an upload queue) (defined in the .changes file) would be the signature of the orig.tar.gz tarball from upstream. And ftp-master could check that the signature (and MD5/SHA1/whatever hash) is valid (i.e. in a trusted keyring) and matches the tar file. However, that should be an *optional* extension as it is common for upstream tar balls to be repackaged (to remove non-free material, for example). And you still have to handle the "trusted" upstream keyring. Which is quite complex. ¿How do yo get keys there? ¿Who verifies them? ¿Do they have to be signed? (I've seen many upstream keys used for distribution which are unsigned, so there's no web of trust) ¿Do you do a per-project check or any key in that keyring is valid? > I could imagine to extend debian/watch to contain a search pattern for You are touching on several issues:
> Or is there already something similar I just don't know? Not that I know of. > I first would like to hear some opinions, before I write some wishlist I think it might be interesting to add these options. But you are looking at more than a single wishlist report (I see at least three, maybe four different places to change). Regards Javier -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Tue Dec 25 14:27:44 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:41 EDT |
||||||||||
|
|||||||||||