Re: One for the Security Guru's

From: Florian Weimer (Weimer@CERT.Uni-Stuttgart.DE)
Date: Wed Nov 06 2002 - 16:39:18 EST


James Cleverdon <jamesclv@us.ibm.com> writes:

> Be surprised: I run "gpg --verify foo.tgz.sign foo.tgz" every time I download
> from kernel.org. And, "rpm --checksig *.rpm" on stuff from redhat.com too.
>
> Given the recent trojaned source packages, I recommend that everyone do the
> same.

Aren't the signatures on kernel.org automatically generated?

-- 
Florian Weimer 	                  Weimer@CERT.Uni-Stuttgart.DE
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-685-5898
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Thu Nov 07 2002 - 22:00:45 EST