|
|||||||||||
|
Re: backports
From: Florian Kulzer <florian.kulzer+debian(at)icfo.es>
Date: Sat Jun 23 2007 - 19:07:45 EDT
[...] > > In backports-users Alexander Wirt wrote: After installing the debian-backports-keyring package I would at least check the signatures of the new key, like this:
$ cd /usr/share/keyrings/
uid Backports.org Archive Key sig! 7E7B8AC9 2005-11-20 Joerg Jaspert sig!3 16BA136C 2005-08-21 Backports.org Archive Key sig!3 16BA136C 2005-08-21 Backports.org Archive Key sub 2048g/5B82CECE 2005-08-21 sig! 16BA136C 2005-08-21 Backports.org Archive Key 1 signature not checked due to a missing key (I have removed all email addresses from the output of the gpg command.) Then you know at least that the new key has been signed by Joerg Jaspert and you checked his signature using his public key from the debian-keyring package. (The second signature cannot be checked because that key is not part of the Debian keyring.) An even better approach would be to download the Backports.org Archive Key manually and to check the signature before adding the new key to apt's keyring. (Installing the debian-backports-keyring package directly means that an unverified post-installation script has root on your computer, therefore you cannot really trust anything after that, including the keys on the Debian keyring.) P.S. The same goes for the debian-multimedia-keyring package. -- Regards, | http://users.icfo.es/Florian.Kulzer Florian | -- To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Sat Jun 23 19:28:58 2007 This archive was generated by hypermail 2.1.8 : Sat Jun 23 2007 - 19:30:02 EDT |
||||||||||
|
|||||||||||