[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: debsums: no md5sums for a lot of important packages on sarge



Alexandros Papadopoulos <apapadop@alumni.cmu.edu> schrieb:
> debsums: no md5sums for ssh

cant reproduce this one. Package ships with md5sums on sarge here.

> So I believe the above output NOT to be the result of a breach. My
> question is, is it acceptable to have so many important and widely
> used packages in *stable* without MD5 checksums?

you cant trust debsums anyway, since the files containing the md5 hashes are
not signed.

> Secondly, how can one fix this on a production system? Is the
> following method proposed by  Paul Gear @
> http://lists.debian.org/debian-security/2005/06/msg00126.html the
> best/only way?

newer debsum versions support creation of sums for packages which do not ship a
md5sum file. 

"debsums can generate checksum lists from deb archives for packages that don't
 include one."

bye,
	- michael



Reply to: