Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207329

Re: Verifying authenticity of Debian CDs

Path csiph.com!3.eu.feeder.erje.net!feeder.erje.net!newsfeed.CARNet.hr!news.spin.it!bofh.it!news.nic.it!robomod
From Default User <hunguponcontent@gmail.com>
Newsgroups linux.debian.user
Subject Re: Verifying authenticity of Debian CDs
Date Thu, 11 Apr 2019 18:40:02 +0200
Message-ID <xLKU2-Rg-11@gated-at.bofh.it> (permalink)
References <xJDWF-3fQ-9@gated-at.bofh.it> <xJFc5-4gL-5@gated-at.bofh.it>
X-Original-To debian-user@lists.debian.org
X-Mailbox-Line From debian-user-request@lists.debian.org Thu Apr 11 16:35:39 2019
Old-Return-Path <hunguponcontent@gmail.com>
X-Amavis-Spam-Status No, score=-5.199 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no autolearn_force=no
X-Policyd-Weight NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .gmail. - helo: .mail-wr1-x442.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=Y0eEEOPb/eGvu0THc7kVpN00G8ASJIisJjpxwZKrlm4ak+L3oXBEqjmVo/DRnOghGO zaJf9o13JzpRAD+PgaLjN9MHKxZpvzfjqw9MLGkR+wQp8zdccPyg8+jQZo/Z50USAhCv M3VrBrc8Qvn7JV0HSyf8YtFqoOyuCcfoB6ZDhBQsXvqn+qJIwP77Z+2HmzNzlc0L95oD 0qcg6Qx162+h4MZddXDjGOcba+8JWzpHBGzb1KuiZaTEipJWosSokRkej9reR08iBojJ OXlFH3L8Gru3KSMobByXasJZjTpAUcFffD+akT7BO/JAUKEr6+lkpVTlu7k0XJ/+SKT1 rXVA==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=ny3SefOfaxqmEFcFPXZH2o7Ub7fy6jBNAgM/Ols3bM4IndyGNJ8+mKcoJWQGGzxZ6C ibthrSTJuEAjJCZjo8xtkOP0Cp7xQVMTlJSb2WQurdWKPMl+JDNOJkB/Uzl0jk7Le+7O 92/xZEE55Qw+VdakYwPcVN/nfiPiuhzYrnnSIAgtlO9bV6zIwDusixwVLXsFg1GCDdv4 B3Ij/pF3qIk6ykKU97NHIg1n13ft9sdK2ia6kALjKT/E/SvDG86H8yTLGGKwhxBz6YUx ee7LOVmmvnE7g7+ytis/dLnu85zvQPSMUmhPCiG7tH3klsIT4hqeDURvUfZnhFOfQy0h 53bA==
X-Gm-Message-State APjAAAW1BhW8BZzodfxTRIy8mBXCys6yLpx7JHy0NAfGk8kF5WQih9V4 heHluav8sT9+h+4IjtvOeuXuYw2cFxRQ9235a2cBBg==
X-Google-SMTP-Source APXvYqyYVj+FrYT0mIO/70iGEa/QG0Y/0MWGeHE/8k95fdAWnhXfNzkxOjGZTE+bEUuW67y/nF/DiBn1PnV4cw54fOo=
X-Received by 2002:adf:b6a3:: with SMTP id j35mr30498378wre.25.1555000523290; Thu, 11 Apr 2019 09:35:23 -0700 (PDT)
MIME-Version 1.0
Content-Type multipart/alternative; boundary="000000000000d0fe1e058643c52d"
X-Mailing-List <debian-user@lists.debian.org> archive/latest/747365
List-ID <debian-user.lists.debian.org>
List-URL <https://lists.debian.org/debian-user/>
List-Archive https://lists.debian.org/msgid-search/CAMaNm6H-otZbk9nZNThj9WkLpaU6qkbEo+oM2v4B8Kfs=3-8CQ@mail.gmail.com
Approved robomod@news.nic.it
Lines 404
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Thu, 11 Apr 2019 12:35:09 -0400
X-Original-Message-ID <CAMaNm6H-otZbk9nZNThj9WkLpaU6qkbEo+oM2v4B8Kfs=3-8CQ@mail.gmail.com>
X-Original-References <CADcNEm8UAtkHdQF-tnfs6i4dvVEcj9J8b_fNcUcAc7i+52qF+w@mail.gmail.com> <10925671283873504605@scdbackup.webframe.org>
Xref csiph.com linux.debian.user:207329

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote:

> Hi,
>
> Chris XX wrote:
> > I was trying to Verify the authenticity of Debian CDs on your website,
> but I
> > don't see instructions that will guide me through the process
> > (step-by-step).
>
> (We are the users. But some Debian Developers are watching, too.)
>
> Obviously there is a gap between checksum file verification and .iso image
> verification.
>
> Let's first look at the files offered for download:
>   https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
> has among others
>
>   SHA512SUMS.sign
>   SHA512SUMS
>   debian-9.8.0-amd64-netinst.iso
>
> > https://www.debian.org/CD/verify
>
> This publishes the key "fingerprints" by which you can recognize authentic
> pairs of SHA512SUMS.sign and SHA512SUMS.
>
> It points to
>   https://keyring.debian.org/
> where you probably shall learn how to obtain the keys in question,
> namely by the shell commands
>
>   gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
>   gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
>   gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3
>
> Experienced users of gpg would know that one can check authenticity by
>
>   gpg --verify SHA512SUMS.sign SHA512SUMS
>
> which should say something like
>
>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
> 6294BE9B
>   gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>   gpg: WARNING: This key is not certified with a trusted signature!
>   gpg:          There is no indication that the signature belongs to the
> owner.
>   Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
> BE9B
>
> The reported fingerprint must be one of the published fingerprints,
> or else something is fishy.
> Here it is the Debian one of 2011-01-05. I.e. all is well so far.
>
> If you change some character in SHA512SUMS and run above command again
> then you will see
>
>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
> 6294BE9B
>   gpg: BAD signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>
>
> So you can trust the content of SHA512SUMS, if gpg --verify says it is
> good and if the key fingerprint matches one of the Debian fingerprints.
>
> Now you have to follow the tiny link "faq" at the bottom to
>   https://www.debian.org/CD/faq/
> where you hop to
>   https://www.debian.org/CD/faq/#verify
>
> Between the lines you read that there is a text line in SHA512SUMS which
> shows the name of the .iso file which you actually want to verify:
>
>
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
> debian-9.8.0-amd64-netinst.iso
>
> More explicite is the hint to use program "sha512sum". A run of
>
>   sha512sum debian-9.8.0-amd64-netinst.iso
>
> puts out
>
>
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
> debian-9.8.0-amd64-netinst.iso
>
> which you should compare with the line in SHA512SUMS.
>
> Alternatively you could run
>
>   sha512sum --check SHA512SUMS 2>/dev/null
>
> to get
>
>   debian-9.8.0-amd64-netinst.iso: OK
>   debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read
>   debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read
>
> Or you could download
>
>   https://people.debian.org/~danchev/debian-iso/check_debian_iso
>
> and run
>
>   chmod u+x ./check_debian_iso
>   ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso
>
> to get
>
>   Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through
> 'sha512sum'
>   to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'.
>   149504+0 records in
>   149504+0 records out
>   306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s
>   Ok: 'debian-9.8.0-amd64-netinst.iso' matches
> 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'
>
>
> Now let's see what happens if a single byte is altered in the .iso
>
>   dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511
> of=debian-9.8.0-amd64-netinst.iso
>
> Now the proposed verifyier runs yield:
>
>
> 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
> debian-9.8.0-amd64-netinst.iso
>
> which does obviously not match the line in SHA512SUMS, or
>
>   debian-9.8.0-amd64-netinst.iso: FAILED
>   ...
>
> or
>
>   ...
>   Found:
>  0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
>   Expected:
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>   MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from
> 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'
>
> So you know that the checksumers really detect nearly all damages of
> debian-9.8.0-amd64-netinst.iso.
>
> --------------------------------------------------------------------------
>
> @ Steve McIntyre (maintainer of debian-cd):
>
> Do you agree with the instructions above ?
>
> Is there a consolidated wiki page with such instructions which i failed
> to find ? If not: shall we make such a page ?
>
>
> Have a nice day :)
>
> Thomas
>


Thomas, thank you for posting this.

It is a good "walk-through" of the verification process. Unfortunately,
proper verification can seem too complicated for some users, especially
newer ones.  So often they just:

sha512 sum debian-9.8.0-amd64-netinst.iso

say, "looks about the same", and call it a day.

Hopefully this will help someone.

Thanks again.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Verifying authenticity of Debian CDs Chris XX <1swansboro@gmail.com> - 2019-04-05 22:50 +0200
  Re: Verifying authenticity of Debian CDs Lee <ler762@gmail.com> - 2019-04-06 00:00 +0200
  Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-06 00:10 +0200
    Re: Verifying authenticity of Debian CDs Default User <hunguponcontent@gmail.com> - 2019-04-11 18:40 +0200
      Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-11 22:30 +0200
    Re: Verifying authenticity of Debian CDs Steve McIntyre <steve@einval.com> - 2019-04-29 19:40 +0200
      Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-29 20:20 +0200
  Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-06 12:30 +0200

csiph-web