|
From: <hzu...@ra...> - 2004-02-09 18:53:27
|
On 02/09/2004 01:34:21 PM Diego Torres wrote: >On Sun, Feb 08, 2004 at 08:10:10PM -0500, Heiko Zuerker wrote: > >> >I mean how do you check the signature if the user did run custom-cd? >> >How do we support security against tempering that way? >> >> Actually the user has to provide his own key pair. It's like the >signing >> of the etc.tar.bz2, the user has to burn his own public key onto the >ISO >> with custom-cd. > >i've been very busy and out for a while. is this gpg stuff configurable >(with other words, can i take this feature off a custom build? :) Do you mean to turn it off ? It's only active when you custom-cd you ISO image and put your public key onto the CD. Heiko |
|
From: <hzu...@ra...> - 2004-02-09 18:54:54
|
On 02/09/2004 03:12:42 AM Friedrich Lobenstock wrote: >Heiko Zuerker wrote on 09.02.2004 02:20 MET: >> Friedrich Lobenstock wrote: >> >>> It has to be done in the initrd anyway and you are not changing those >>> libraries when doing the update. And yes this might be a problem of >>> its own, we can not change the initrd anymore. Hmmmmm.....then initrd >>> needs some fixed parts (does not change across stable version) which >>> loads the varibale ones, taking into account to update those if an >>> "update CD" exists. Then the rest of the system is updated. Now this >>> might also be a good idea to include the update script _from_ CD. >This >>> way we can provide for a more complicated if we did not think about a >>> specific update problem later and as this script is tamper proof (on >>> CD!) it can check all the signatures against a provided signature >file >>> (is that really needed?). >> >> >> Since all update functions are on the CD anyway (pre_init script), the >> existance of this script would be the only requirement. >> >> This would be the procedure: >> 1. initrd loads >> 2. initrd replaces bootcd.iso with bootcd.iso.new (after verifying it) >> 3. initrd continues as usual >> 4. pre_init sees the CD version is different to the config version and >> performs an update (interactive part already implemented). > >What do you do if initrd has to be updated? I would suggest that the pre_init script takes care of this. The correct initrd.gz is on the ISO image and just needs to be copied over onto the usb stick or whatever is used. Heiko |
|
From: Friedrich L. <fl...@fl...> - 2004-02-09 19:05:02
|
hzu...@ra... wrote on 09.02.2004 19:54 MET: > On 02/09/2004 03:12:42 AM Friedrich Lobenstock wrote: > >>Heiko Zuerker wrote on 09.02.2004 02:20 MET: >> >>>Friedrich Lobenstock wrote: >>> >>> >>>>It has to be done in the initrd anyway and you are not changing those >>>>libraries when doing the update. And yes this might be a problem of >>>>its own, we can not change the initrd anymore. Hmmmmm.....then initrd >>>>needs some fixed parts (does not change across stable version) which >>>>loads the varibale ones, taking into account to update those if an >>>>"update CD" exists. Then the rest of the system is updated. Now this >>>>might also be a good idea to include the update script _from_ CD. >> >>This >> >>>>way we can provide for a more complicated if we did not think about a >>>>specific update problem later and as this script is tamper proof (on >>>>CD!) it can check all the signatures against a provided signature >> >>file >> >>>>(is that really needed?). >>> >>> >>>Since all update functions are on the CD anyway (pre_init script), the >>>existance of this script would be the only requirement. >>> >>>This would be the procedure: >>>1. initrd loads >>>2. initrd replaces bootcd.iso with bootcd.iso.new (after verifying it) >>>3. initrd continues as usual >>>4. pre_init sees the CD version is different to the config version and >>>performs an update (interactive part already implemented). >> >>What do you do if initrd has to be updated? > > > I would suggest that the pre_init script takes care of this. The correct > initrd.gz is on the ISO image and just needs to be copied over onto the usb > stick or whatever is used. Then direct after the upgrade a reboot has to be forced to activate the new initrd, I think. Or would you give the initrd's a version number so you can distinguish if a forced reboot is needed or not? -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Heiko Z. <he...@zu...> - 2004-02-09 19:36:18
|
> hzu...@ra... wrote on 09.02.2004 19:54 MET: >> On 02/09/2004 03:12:42 AM Friedrich Lobenstock wrote: >> >>>Heiko Zuerker wrote on 09.02.2004 02:20 MET: >>> >>>>Friedrich Lobenstock wrote: >>>> >>>> >>>>>It has to be done in the initrd anyway and you are not changing those >>>>>libraries when doing the update. And yes this might be a problem of >>>>>its own, we can not change the initrd anymore. Hmmmmm.....then initrd >>>>>needs some fixed parts (does not change across stable version) which >>>>>loads the varibale ones, taking into account to update those if an >>>>>"update CD" exists. Then the rest of the system is updated. Now this >>>>>might also be a good idea to include the update script _from_ CD. >>> >>>This >>> >>>>>way we can provide for a more complicated if we did not think about a >>>>>specific update problem later and as this script is tamper proof (on >>>>>CD!) it can check all the signatures against a provided signature >>> >>>file >>> >>>>>(is that really needed?). >>>> >>>> >>>>Since all update functions are on the CD anyway (pre_init script), the >>>>existance of this script would be the only requirement. >>>> >>>>This would be the procedure: >>>>1. initrd loads >>>>2. initrd replaces bootcd.iso with bootcd.iso.new (after verifying it) >>>>3. initrd continues as usual >>>>4. pre_init sees the CD version is different to the config version and >>>>performs an update (interactive part already implemented). >>> >>>What do you do if initrd has to be updated? >> >> >> I would suggest that the pre_init script takes care of this. The correct >> initrd.gz is on the ISO image and just needs to be copied over onto the >> usb >> stick or whatever is used. > > Then direct after the upgrade a reboot has to be forced to activate the > new > initrd, I think. Or would you give the initrd's a version number so you > can > distinguish if a forced reboot is needed or not? Hmmm..... I think we should force a boot whenever we updated the initrd. This would be the easy way. ;-) -- Regards Heiko Zuerker http://www.devil-linux.org |