|
From: <hzu...@ra...> - 2004-01-12 15:37:00
|
On 01/12/2004 09:57:57 AM Friedrich Lobenstock wrote: >Oliver Jehle wrote on 12.01.2004 15:52 MET: >> >> another questions, are there plans to sign the source packages ???? >> only a litte but important thing :-) > >Maybe we should at least do md5sums automatically in the update script. >That should be enough for now I think. Good idea Heiko |
|
From: Friedrich L. <fl...@fl...> - 2004-01-12 16:37:04
|
hzu...@ra... wrote on 12.01.2004 16:36 MET: > On 01/12/2004 09:57:57 AM Friedrich Lobenstock wrote: > >>Oliver Jehle wrote on 12.01.2004 15:52 MET: >> >>>another questions, are there plans to sign the source packages ???? >>>only a litte but important thing :-) >> >>Maybe we should at least do md5sums automatically in the update script. >>That should be enough for now I think. > > > Good idea Already filed a feature request. I think the best way is that we create for eg. archive.tar.bz2 a file archive.tar.bz2.md5sum. This was we can easily automate the task of checking every file while at the same time decoupling it from one single ftp maintainer who would create on big md5sum file for all files. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2004-01-12 16:49:36
|
> >>>another questions, are there plans to sign the source packages ???? > >>>only a litte but important thing :-) > >> > >>Maybe we should at least do md5sums automatically in the update script. > >>That should be enough for now I think. > > > > > > Good idea > > Already filed a feature request. > > I think the best way is that we create for eg. archive.tar.bz2 > a file archive.tar.bz2.md5sum. This was we can easily automate > the task of checking every file while at the same time decoupling > it from one single ftp maintainer who would create on big md5sum > file for all files. While this is a great idea to ensure the downloads are good, it does nothing to prevent what happened at Debian. If someone breaks into the FTP site, they can easily create a new md5sum file after they change the source code. We really need some kind of a signed file to prevent that. Or at least keep the md5sum files on a different server. - BS |
|
From: Friedrich L. <fl...@fl...> - 2004-01-12 17:39:16
|
Bruce Smith wrote on 12.01.2004 17:49 MET: >>>>>another questions, are there plans to sign the source packages ???? >>>>>only a litte but important thing :-) >>>> >>>>Maybe we should at least do md5sums automatically in the update script. >>>>That should be enough for now I think. >>> >>> >>>Good idea >> >>Already filed a feature request. >> >>I think the best way is that we create for eg. archive.tar.bz2 >>a file archive.tar.bz2.md5sum. This was we can easily automate >>the task of checking every file while at the same time decoupling >>it from one single ftp maintainer who would create on big md5sum >>file for all files. > > > While this is a great idea to ensure the downloads are good, it does > nothing to prevent what happened at Debian. If someone breaks into the > FTP site, they can easily create a new md5sum file after they change the > source code. We really need some kind of a signed file to prevent > that. Or at least keep the md5sum files on a different server. Than every developer who can upload files to the ftp server needs to sign each md5sum file he uploads, right?. That would mean GPG needs to be installed in the lfs system right from the beginning. The kexring can't be in CVS either, so that would mean at start a developer has to initialize the keyring with all the GPG/PGP public certificates. It always get's more complicated... -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2004-01-12 18:29:16
|
> > While this is a great idea to ensure the downloads are good, it does > > nothing to prevent what happened at Debian. If someone breaks into the > > FTP site, they can easily create a new md5sum file after they change the > > source code. We really need some kind of a signed file to prevent > > that. Or at least keep the md5sum files on a different server. > > Than every developer who can upload files to the ftp server needs > to sign each md5sum file he uploads, right?. Probably be easier than signing the tar files. :-) > That would mean GPG needs to be installed in the lfs system right > from the beginning. Or on the host Linux, especially since you can't download the source from within the LFS chroot anyway. We could make GPG required on the host Linux, like lftp. > The kexring can't be in CVS either, Why not? It's a different server. Different access/passwords, and if someone changed it, we'd be notified by email on the commit list. > so that would mean at start a developer has to initialize the keyring > with all the GPG/PGP public certificates. Maybe the keys could be installed on the local system once? Redhat does it something like that with their RPM's. You download the keys once, which are installed on the local Redhat system. Then RPM automatically checks the signatures when installing a RPM file. This is all just theory on my part, since I've never actually setup anything like this. Feel free to blow holes in my ideas. > It always get's more complicated... I didn't say it would be easy!!! ;-) Just pointing out that md5sum does not solve the original concern. - BS |
|
From: Friedrich L. <fl...@fl...> - 2004-01-12 19:15:48
|
Bruce Smith wrote on 12.01.2004 19:29 MET: >>>While this is a great idea to ensure the downloads are good, it does >>>nothing to prevent what happened at Debian. If someone breaks into the >>>FTP site, they can easily create a new md5sum file after they change the >>>source code. We really need some kind of a signed file to prevent >>>that. Or at least keep the md5sum files on a different server. >> >>Than every developer who can upload files to the ftp server needs >>to sign each md5sum file he uploads, right?. > > > Probably be easier than signing the tar files. :-) > > >>That would mean GPG needs to be installed in the lfs system right >>from the beginning. > > > Or on the host Linux, especially since you can't download the source > from within the LFS chroot anyway. You can for sure download chrooted to the lfs system. You probably have to copy your /etc/resolv.conf to corresponding directory of the lfs system. Done that for a long time. So the only commands we need from the host Linux are basically chroot, cvs, diff and ssh. > We could make GPG required on the host Linux, like lftp. If we have it in the lfs system everybody has for sure the same environment. >>The kexring can't be in CVS either, > > > Why not? It's a different server. Different access/passwords, and > if someone changed it, we'd be notified by email on the commit list. Ok, good point, so lets put it there. >>so that would mean at start a developer has to initialize the keyring >>with all the GPG/PGP public certificates. > > > Maybe the keys could be installed on the local system once? > > Redhat does it something like that with their RPM's. You download the > keys once, which are installed on the local Redhat system. Then RPM > automatically checks the signatures when installing a RPM file. > > This is all just theory on my part, since I've never actually setup > anything like this. Feel free to blow holes in my ideas. If the keyring is in CVS do a checkout or update and then chrooted to the lfs system now you should be able to use gpg. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2004-01-12 19:29:11
|
> > Or on the host Linux, especially since you can't download the source > > from within the LFS chroot anyway. > > You can for sure download chrooted to the lfs system. You probably > have to copy your /etc/resolv.conf to corresponding directory of the > lfs system. Done that for a long time. You're right, cool! :-) I've never bothered to try and get it working. > If we have it in the lfs system everybody has for sure the > same environment. How do we protect the lfssystem...tar file itself? Someone could cause us real problems by changing that file. - BS |
|
From: Friedrich L. <fl...@fl...> - 2004-01-12 19:48:46
|
Bruce Smith wrote on 12.01.2004 20:29 MET: > > How do we protect the lfssystem...tar file itself? > Someone could cause us real problems by changing that file. The same md5sum file signed. Then on the homepage we put up the info how to download the public keys that correspond to the signing keys. The keys can also be checked-in into CVS I think. So then a very curiouse person will get the public key from cvs and from a pgp keyserver to be sure to have the correct one. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |