On Sun, Jul 29, 2001 at 02:51:37PM +0200, Wichert Akkerman wrote: > Previously Marcus Brinkmann wrote: > > The packages are signed. The whole release will be signed, as far as I > > know. So I can verify these signatures and know they are the official > > Debian CD images. > > That last bit is still an issue, apparently the current apt does not > handle that and Jason doesn't seem willing to fix that. Eric Gillespie and I wrote a tool for Progeny called apt-checksigs that addresses this problem. However, it depends on modifications to dpkg that I do not think have made it out of dpkg CVS yet. It can be found at <http://people.debian.org/~branden/apt-checksigs/>. (Needless to say, it is licensed under the GPL.) -- G. Branden Robinson | A committee is a life form with six or Debian GNU/Linux | more legs and no brain. branden@debian.org | -- Robert Heinlein http://people.debian.org/~branden/ |
Attachment:
pgp44FvZ2MPwQ.pgp
Description: PGP signature