Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Debian packages without md5sums

From: Andrew Sackville-West <andrew(at)farwestbilliards.com>
Date: Tue Sep 11 2007 - 14:15:53 EDT


On Mon, Sep 10, 2007 at 09:17:59PM +0000, Felix Karpfen wrote:
>
> The fault is mine/my setup. My connection to the internet is slow;
> hence I am reduced to using the DVDs for upgrades. Although I procured
> the "official" Etch DVD set from a supplier listed by Debian, there were
> numerous notifications during the "dist-upgrade" that I was installing
> "untrusted packages". And, due to my slow internet connection, I refrained
> from running the recommended "aptitude update" at the end of the
> successful "dist-upgrade".

these errors (untrusted packages) have to do with the new secure-apt system which uses gpg keys to confirm the signatures on packages. Install the debian-archive-keyring package and then update.

>
> Is there an alternative to "aptitude update" or do I have to live with the
> missing md5sums and "untrusted packages"?

there is not really any alternative to "aptitude update" unless you consider some other apt front-end an alternative (apt-get, synaptic) but they all do the same thing. The missing md5 sums has nothing to do with the trusted/untrusted packages issue.

In theory, you have installed packages that may be compromised due to the failure to check the signatures. In practice, this is probably not a real issue. You could pull known-good debs from somewhere and compare md5sums to confirm that your installation is good, but its probably not worth the effort, unless you have some reason to be concerned about compromise.

You definitely should make sure you read up on the debian-archive-keyring and get it installed and working properly.

A

-- 
To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Tue Sep 11 14:16:30 2007
Do you need help?X

This archive was generated by hypermail 2.1.8 : Sun Oct 07 2007 - 04:23:00 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library