Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #55245 > unrolled thread

Wishlist meta-bug? Explain 'unsigned' in package name

Started byRichard Hector <richard@walnut.gen.nz>
First post2016-09-28 03:20 +0200
Last post2016-09-29 15:20 +0200
Articles 5 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  Wishlist meta-bug? Explain 'unsigned' in package name Richard Hector <richard@walnut.gen.nz> - 2016-09-28 03:20 +0200
    Re: Wishlist meta-bug? Explain 'unsigned' in package name Ben Hutchings <ben@decadent.org.uk> - 2016-09-28 14:10 +0200
      Re: Wishlist meta-bug? Explain 'unsigned' in package name Richard Hector <richard@walnut.gen.nz> - 2016-09-28 16:00 +0200
        Re: Wishlist meta-bug? Explain 'unsigned' in package name Ben Hutchings <ben@decadent.org.uk> - 2016-09-29 13:10 +0200
          Re: Wishlist meta-bug? Explain 'unsigned' in package name Richard Hector <richard@walnut.gen.nz> - 2016-09-29 15:20 +0200

#55245 — Wishlist meta-bug? Explain 'unsigned' in package name

FromRichard Hector <richard@walnut.gen.nz>
Date2016-09-28 03:20 +0200
SubjectWishlist meta-bug? Explain 'unsigned' in package name
Message-ID<smbHr-87-3@gated-at.bofh.it>
Hi - I can create a bug for this if required, but it seems a bit meta
and trivial.

Can the description of packages with '-unsigned' in the name include an
explanation of what 'unsigned' means in this context?

I understand now it relates to Secure Boot, but initially I was worried
that I was installing an unsigned and therefore potentially untrusted
package.

Thanks,
Richard

[toc] | [next] | [standalone]


#55250

FromBen Hutchings <ben@decadent.org.uk>
Date2016-09-28 14:10 +0200
Message-ID<smlQu-6sb-11@gated-at.bofh.it>
In reply to#55245

[Multipart message — attachments visible in raw view] — view raw

On Wed, 2016-09-28 at 14:01 +1300, Richard Hector wrote:
> Hi - I can create a bug for this if required, but it seems a bit meta
> and trivial.
> 
> Can the description of packages with '-unsigned' in the name include an
> explanation of what 'unsigned' means in this context?
> 
> I understand now it relates to Secure Boot, but initially I was worried
> that I was installing an unsigned and therefore potentially untrusted
> package.

If '-unsigned' dissuades users from installing it, I'm quite happy with
that.  The packages with signed code should be used by default.

We could improve the descriptions to make this clearer, but it would
require changes in both linux and linux-signed - currently the latter
copies the unsigned package's description and adds '(signed)' to the
first line.

Ben.

-- 
Ben Hutchings
If the facts do not conform to your theory, they must be disposed of.

[toc] | [prev] | [next] | [standalone]


#55254

FromRichard Hector <richard@walnut.gen.nz>
Date2016-09-28 16:00 +0200
Message-ID<smnyV-7th-17@gated-at.bofh.it>
In reply to#55250
On 29/09/16 01:05, Ben Hutchings wrote:
> On Wed, 2016-09-28 at 14:01 +1300, Richard Hector wrote:
>> Hi - I can create a bug for this if required, but it seems a bit
>> meta and trivial.
>> 
>> Can the description of packages with '-unsigned' in the name
>> include an explanation of what 'unsigned' means in this context?
>> 
>> I understand now it relates to Secure Boot, but initially I was
>> worried that I was installing an unsigned and therefore
>> potentially untrusted package.
> 
> If '-unsigned' dissuades users from installing it, I'm quite happy
> with that.  The packages with signed code should be used by
> default.

Oh, ok - so when I installed linux-image-4.7.0-0.bpo.1-amd64-unsigned,
assuming it to be the natural successor to the now obsolete
linux-image-4.6.0-0.bpo.1-amd64 (generally following
jessie-backports), that wasn't really the right thing to do?

Or was it a mistake that the 4.7 unsigned kernel got into backports
instead of the signed one in the first place?

Anyway, it seems unfortunate that there now appears to be no
trustworthy bpo kernel for those of us with needy hardware :-(

Cheers,
Richard

[toc] | [prev] | [next] | [standalone]


#55257

FromBen Hutchings <ben@decadent.org.uk>
Date2016-09-29 13:10 +0200
Message-ID<smHnX-3mW-9@gated-at.bofh.it>
In reply to#55254

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2016-09-29 at 02:54 +1300, Richard Hector wrote:
> On 29/09/16 01:05, Ben Hutchings wrote:
> > 
> > On Wed, 2016-09-28 at 14:01 +1300, Richard Hector wrote:
> > > 
> > > Hi - I can create a bug for this if required, but it seems a bit
> > > meta and trivial.
> > > 
> > > Can the description of packages with '-unsigned' in the name
> > > include an explanation of what 'unsigned' means in this context?
> > > 
> > > I understand now it relates to Secure Boot, but initially I was
> > > worried that I was installing an unsigned and therefore
> > > potentially untrusted package.
> > 
> > If '-unsigned' dissuades users from installing it, I'm quite happy
> > with that.  The packages with signed code should be used by
> > default.
> 
> Oh, ok - so when I installed linux-image-4.7.0-0.bpo.1-amd64-unsigned,
> assuming it to be the natural successor to the now obsolete
> linux-image-4.6.0-0.bpo.1-amd64 (generally following
> jessie-backports), that wasn't really the right thing to do?
> 
> Or was it a mistake that the 4.7 unsigned kernel got into backports
> instead of the signed one in the first place?

It was a mistake that that was uploaded, since jessie-backports is
supposed to be based on testing which still has 4.6.

> Anyway, it seems unfortunate that there now appears to be no
> trustworthy bpo kernel for those of us with needy hardware :-(

This should get sorted out by the end of the week.

Ben.

-- 
Ben Hutchings
If the facts do not conform to your theory, they must be disposed of.

[toc] | [prev] | [next] | [standalone]


#55260

FromRichard Hector <richard@walnut.gen.nz>
Date2016-09-29 15:20 +0200
Message-ID<smJpL-4Ah-15@gated-at.bofh.it>
In reply to#55257
On 30/09/16 00:09, Ben Hutchings wrote:
>>> Anyway, it seems unfortunate that there now appears to be no 
>>> trustworthy bpo kernel for those of us with needy hardware :-(
> This should get sorted out by the end of the week.

Great, thanks :-)

Richard

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web