On Thu, Jan 23, 2003 at 03:47:37PM +0100, Qian Gong wrote: > Hi, > > Is it possible to download only md5sum's of the files in debian packages > from a trusted server, e.g., security.debian.org? If it is, the integrity > of installed packages can be safely verified with the trusted source. And > the downloaded file would be small. Thanks a lot. Sure. Get the Packages{.gz,.bz2,} file from your local trusted Debian mirror, it contains md5sum's for every package in it's distribution. Of course, then the problem is verifying the authenticity and accuracy of the Packages file... -rob
Attachment:
pgp4OKCSjkfz2.pgp
Description: PGP signature