Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.security > #6228

Re: timestamp of the signature of Debian 12 netinst

From Julian Schreck <js-priv@online.de>
Newsgroups linux.debian.security
Subject Re: timestamp of the signature of Debian 12 netinst
Date 2023-06-23 21:00 +0200
Message-ID <GJUaJ-okR-3@gated-at.bofh.it> (permalink)
References (1 earlier) <GJQqt-lPn-9@gated-at.bofh.it> <GJQqt-lPn-11@gated-at.bofh.it> <GJQqt-lPn-13@gated-at.bofh.it> <GJQqt-lPn-5@gated-at.bofh.it> <GJRFT-mYM-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Where to find the former? (Or do I not need it for checking the integrity of the download(s)?)
--
> On Fri, 2023-06-23 at 16:53 +0200, Julian Schreck wrote:
> > I was downloading the netimage of bookworm, the signing key(s) and
> > sha sums when I noticed that my timestamp of the signature [0]
> > differs from the one on the website. [1]
> > Is this a security issue or just a website not updated?
> > 
> 
> You appear to be comparing two entirely different things, and expecting
> them to match.
> 
> > -
> > [0] :
> > $ LC_ALL=C gpg --verify-files SHA512SUMS.sign
> > gpg: assuming signed data in 'SHA512SUMS'
> > gpg: Signature made Sat Jun 10 15:58:35 2023 CEST
> > gpg:                using RSA key
> > DF9B9C49EAA9298432589D76DA87E80D6294BE9B
> > 
> 
> This is the date and time that the signature for the SHA512SUMS file
> was produced. Whereas this:
> 
> [...]
> > [1] : https://www.debian.org/CD/verify, e. g. 2011-01-05 [SC]
> 
> is the date when the key was created.
> 
> It would be very surprising if they *did* match.
> 
> Regards,
> 
> Adam

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-23 17:00 +0200
  Re: timestamp of the signature of Debian 12 netinst "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2023-06-23 18:20 +0200
    Re: timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-23 21:00 +0200
      Re: timestamp of the signature of Debian 12 netinst Jeremy Stanley <fungi@yuggoth.org> - 2023-06-23 22:20 +0200
        Re: timestamp of the signature of Debian 12 netinst Jonathan Wiltshire <jmw@debian.org> - 2023-06-24 20:30 +0200
        Re: timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-24 20:30 +0200
  Re: timestamp of the signature of Debian 12 netinst Jonathan Wiltshire <jmw@debian.org> - 2023-06-23 19:10 +0200

csiph-web