Re: Howto verify packages with apt-get (gpg?)

2002-11-30 Thread Fred Bowman
Benjamin Schulz schrieb: how can i proof, that the package is ok? md5sum is not satisfactory. why not? imagine that a package, which is provided on a server, is manipulated (trojan). there would be no problem for the bad guy to manipulate the md5sum, too (if provided on the same server).

Re: Howto verify packages with apt-get (gpg?)

2002-11-30 Thread Fred Bowman
Benjamin Schulz schrieb: how can i proof, that the package is ok? md5sum is not satisfactory. why not? imagine that a package, which is provided on a server, is manipulated (trojan). there would be no problem for the bad guy to manipulate the md5sum, too (if provided on the same server).

Howto verify packages with apt-get (gpg?)

2002-11-29 Thread Fred Bowman
hi there. are debian packages signed with pgp or something similar? how can packages be verified? for example, if i want to install the openssl package with #apt-get install openssl how can i proof, that the package is ok? md5sum is not satisfactory. i checked the debian webpage, faq and searc

Howto verify packages with apt-get (gpg?)

2002-11-29 Thread Fred Bowman
hi there. are debian packages signed with pgp or something similar? how can packages be verified? for example, if i want to install the openssl package with #apt-get install openssl how can i proof, that the package is ok? md5sum is not satisfactory. i checked the debian webpage, faq and search