Re: debsums: no md5sums for a lot of important packages on sarge
Alexandros Papadopoulos <apapadop@alumni.cmu.edu> schrieb:
> debsums: no md5sums for ssh
cant reproduce this one. Package ships with md5sums on sarge here.
> So I believe the above output NOT to be the result of a breach. My
> question is, is it acceptable to have so many important and widely
> used packages in *stable* without MD5 checksums?
you cant trust debsums anyway, since the files containing the md5 hashes are
not signed.
> Secondly, how can one fix this on a production system? Is the
> following method proposed by Paul Gear @
> http://lists.debian.org/debian-security/2005/06/msg00126.html the
> best/only way?
newer debsum versions support creation of sums for packages which do not ship a
md5sum file.
"debsums can generate checksum lists from deb archives for packages that don't
include one."
bye,
- michael
Reply to: