Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #207329
| Path | csiph.com!3.eu.feeder.erje.net!feeder.erje.net!newsfeed.CARNet.hr!news.spin.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | Default User <hunguponcontent@gmail.com> |
| Newsgroups | linux.debian.user |
| Subject | Re: Verifying authenticity of Debian CDs |
| Date | Thu, 11 Apr 2019 18:40:02 +0200 |
| Message-ID | <xLKU2-Rg-11@gated-at.bofh.it> (permalink) |
| References | <xJDWF-3fQ-9@gated-at.bofh.it> <xJFc5-4gL-5@gated-at.bofh.it> |
| X-Original-To | debian-user@lists.debian.org |
| X-Mailbox-Line | From debian-user-request@lists.debian.org Thu Apr 11 16:35:39 2019 |
| Old-Return-Path | <hunguponcontent@gmail.com> |
| X-Amavis-Spam-Status | No, score=-5.199 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no autolearn_force=no |
| X-Policyd-Weight | NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .gmail. - helo: .mail-wr1-x442.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5 |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=Y0eEEOPb/eGvu0THc7kVpN00G8ASJIisJjpxwZKrlm4ak+L3oXBEqjmVo/DRnOghGO zaJf9o13JzpRAD+PgaLjN9MHKxZpvzfjqw9MLGkR+wQp8zdccPyg8+jQZo/Z50USAhCv M3VrBrc8Qvn7JV0HSyf8YtFqoOyuCcfoB6ZDhBQsXvqn+qJIwP77Z+2HmzNzlc0L95oD 0qcg6Qx162+h4MZddXDjGOcba+8JWzpHBGzb1KuiZaTEipJWosSokRkej9reR08iBojJ OXlFH3L8Gru3KSMobByXasJZjTpAUcFffD+akT7BO/JAUKEr6+lkpVTlu7k0XJ/+SKT1 rXVA== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=ny3SefOfaxqmEFcFPXZH2o7Ub7fy6jBNAgM/Ols3bM4IndyGNJ8+mKcoJWQGGzxZ6C ibthrSTJuEAjJCZjo8xtkOP0Cp7xQVMTlJSb2WQurdWKPMl+JDNOJkB/Uzl0jk7Le+7O 92/xZEE55Qw+VdakYwPcVN/nfiPiuhzYrnnSIAgtlO9bV6zIwDusixwVLXsFg1GCDdv4 B3Ij/pF3qIk6ykKU97NHIg1n13ft9sdK2ia6kALjKT/E/SvDG86H8yTLGGKwhxBz6YUx ee7LOVmmvnE7g7+ytis/dLnu85zvQPSMUmhPCiG7tH3klsIT4hqeDURvUfZnhFOfQy0h 53bA== |
| X-Gm-Message-State | APjAAAW1BhW8BZzodfxTRIy8mBXCys6yLpx7JHy0NAfGk8kF5WQih9V4 heHluav8sT9+h+4IjtvOeuXuYw2cFxRQ9235a2cBBg== |
| X-Google-SMTP-Source | APXvYqyYVj+FrYT0mIO/70iGEa/QG0Y/0MWGeHE/8k95fdAWnhXfNzkxOjGZTE+bEUuW67y/nF/DiBn1PnV4cw54fOo= |
| X-Received | by 2002:adf:b6a3:: with SMTP id j35mr30498378wre.25.1555000523290; Thu, 11 Apr 2019 09:35:23 -0700 (PDT) |
| MIME-Version | 1.0 |
| Content-Type | multipart/alternative; boundary="000000000000d0fe1e058643c52d" |
| X-Mailing-List | <debian-user@lists.debian.org> archive/latest/747365 |
| List-ID | <debian-user.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-user/> |
| List-Archive | https://lists.debian.org/msgid-search/CAMaNm6H-otZbk9nZNThj9WkLpaU6qkbEo+oM2v4B8Kfs=3-8CQ@mail.gmail.com |
| Approved | robomod@news.nic.it |
| Lines | 404 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Thu, 11 Apr 2019 12:35:09 -0400 |
| X-Original-Message-ID | <CAMaNm6H-otZbk9nZNThj9WkLpaU6qkbEo+oM2v4B8Kfs=3-8CQ@mail.gmail.com> |
| X-Original-References | <CADcNEm8UAtkHdQF-tnfs6i4dvVEcj9J8b_fNcUcAc7i+52qF+w@mail.gmail.com> <10925671283873504605@scdbackup.webframe.org> |
| Xref | csiph.com linux.debian.user:207329 |
Show key headers only | View raw
[Multipart message — attachments visible in raw view] - view raw
On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote: > Hi, > > Chris XX wrote: > > I was trying to Verify the authenticity of Debian CDs on your website, > but I > > don't see instructions that will guide me through the process > > (step-by-step). > > (We are the users. But some Debian Developers are watching, too.) > > Obviously there is a gap between checksum file verification and .iso image > verification. > > Let's first look at the files offered for download: > https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/ > has among others > > SHA512SUMS.sign > SHA512SUMS > debian-9.8.0-amd64-netinst.iso > > > https://www.debian.org/CD/verify > > This publishes the key "fingerprints" by which you can recognize authentic > pairs of SHA512SUMS.sign and SHA512SUMS. > > It points to > https://keyring.debian.org/ > where you probably shall learn how to obtain the keys in question, > namely by the shell commands > > gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D > gpg --keyserver keyring.debian.org --recv-keys 6294BE9B > gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3 > > Experienced users of gpg would know that one can check authenticity by > > gpg --verify SHA512SUMS.sign SHA512SUMS > > which should say something like > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: Good signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. > Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 > BE9B > > The reported fingerprint must be one of the published fingerprints, > or else something is fishy. > Here it is the Debian one of 2011-01-05. I.e. all is well so far. > > If you change some character in SHA512SUMS and run above command again > then you will see > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: BAD signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > > > So you can trust the content of SHA512SUMS, if gpg --verify says it is > good and if the key fingerprint matches one of the Debian fingerprints. > > Now you have to follow the tiny link "faq" at the bottom to > https://www.debian.org/CD/faq/ > where you hop to > https://www.debian.org/CD/faq/#verify > > Between the lines you read that there is a text line in SHA512SUMS which > shows the name of the .iso file which you actually want to verify: > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > More explicite is the hint to use program "sha512sum". A run of > > sha512sum debian-9.8.0-amd64-netinst.iso > > puts out > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > which you should compare with the line in SHA512SUMS. > > Alternatively you could run > > sha512sum --check SHA512SUMS 2>/dev/null > > to get > > debian-9.8.0-amd64-netinst.iso: OK > debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read > debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read > > Or you could download > > https://people.debian.org/~danchev/debian-iso/check_debian_iso > > and run > > chmod u+x ./check_debian_iso > ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso > > to get > > Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through > 'sha512sum' > to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'. > 149504+0 records in > 149504+0 records out > 306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s > Ok: 'debian-9.8.0-amd64-netinst.iso' matches > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > > Now let's see what happens if a single byte is altered in the .iso > > dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511 > of=debian-9.8.0-amd64-netinst.iso > > Now the proposed verifyier runs yield: > > > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > debian-9.8.0-amd64-netinst.iso > > which does obviously not match the line in SHA512SUMS, or > > debian-9.8.0-amd64-netinst.iso: FAILED > ... > > or > > ... > Found: > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > Expected: > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > So you know that the checksumers really detect nearly all damages of > debian-9.8.0-amd64-netinst.iso. > > -------------------------------------------------------------------------- > > @ Steve McIntyre (maintainer of debian-cd): > > Do you agree with the instructions above ? > > Is there a consolidated wiki page with such instructions which i failed > to find ? If not: shall we make such a page ? > > > Have a nice day :) > > Thomas > Thomas, thank you for posting this. It is a good "walk-through" of the verification process. Unfortunately, proper verification can seem too complicated for some users, especially newer ones. So often they just: sha512 sum debian-9.8.0-amd64-netinst.iso say, "looks about the same", and call it a day. Hopefully this will help someone. Thanks again.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Verifying authenticity of Debian CDs Chris XX <1swansboro@gmail.com> - 2019-04-05 22:50 +0200
Re: Verifying authenticity of Debian CDs Lee <ler762@gmail.com> - 2019-04-06 00:00 +0200
Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-06 00:10 +0200
Re: Verifying authenticity of Debian CDs Default User <hunguponcontent@gmail.com> - 2019-04-11 18:40 +0200
Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-11 22:30 +0200
Re: Verifying authenticity of Debian CDs Steve McIntyre <steve@einval.com> - 2019-04-29 19:40 +0200
Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-29 20:20 +0200
Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-06 12:30 +0200
csiph-web