Path: csiph.com!3.eu.feeder.erje.net!feeder.erje.net!newsfeed.CARNet.hr!news.spin.it!bofh.it!news.nic.it!robomod From: Default User Newsgroups: linux.debian.user Subject: Re: Verifying authenticity of Debian CDs Date: Thu, 11 Apr 2019 18:40:02 +0200 Message-ID: References: X-Original-To: debian-user@lists.debian.org X-Mailbox-Line: From debian-user-request@lists.debian.org Thu Apr 11 16:35:39 2019 Old-Return-Path: X-Amavis-Spam-Status: No, score=-5.199 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no autolearn_force=no X-Policyd-Weight: NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .gmail. - helo: .mail-wr1-x442.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5 Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=Y0eEEOPb/eGvu0THc7kVpN00G8ASJIisJjpxwZKrlm4ak+L3oXBEqjmVo/DRnOghGO zaJf9o13JzpRAD+PgaLjN9MHKxZpvzfjqw9MLGkR+wQp8zdccPyg8+jQZo/Z50USAhCv M3VrBrc8Qvn7JV0HSyf8YtFqoOyuCcfoB6ZDhBQsXvqn+qJIwP77Z+2HmzNzlc0L95oD 0qcg6Qx162+h4MZddXDjGOcba+8JWzpHBGzb1KuiZaTEipJWosSokRkej9reR08iBojJ OXlFH3L8Gru3KSMobByXasJZjTpAUcFffD+akT7BO/JAUKEr6+lkpVTlu7k0XJ/+SKT1 rXVA== X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=wy/Dgoh2o+IWlXHWcmmtUWeEgYoNxoWPuYioJBpRoyk=; b=ny3SefOfaxqmEFcFPXZH2o7Ub7fy6jBNAgM/Ols3bM4IndyGNJ8+mKcoJWQGGzxZ6C ibthrSTJuEAjJCZjo8xtkOP0Cp7xQVMTlJSb2WQurdWKPMl+JDNOJkB/Uzl0jk7Le+7O 92/xZEE55Qw+VdakYwPcVN/nfiPiuhzYrnnSIAgtlO9bV6zIwDusixwVLXsFg1GCDdv4 B3Ij/pF3qIk6ykKU97NHIg1n13ft9sdK2ia6kALjKT/E/SvDG86H8yTLGGKwhxBz6YUx ee7LOVmmvnE7g7+ytis/dLnu85zvQPSMUmhPCiG7tH3klsIT4hqeDURvUfZnhFOfQy0h 53bA== X-Gm-Message-State: APjAAAW1BhW8BZzodfxTRIy8mBXCys6yLpx7JHy0NAfGk8kF5WQih9V4 heHluav8sT9+h+4IjtvOeuXuYw2cFxRQ9235a2cBBg== X-Google-SMTP-Source: APXvYqyYVj+FrYT0mIO/70iGEa/QG0Y/0MWGeHE/8k95fdAWnhXfNzkxOjGZTE+bEUuW67y/nF/DiBn1PnV4cw54fOo= X-Received: by 2002:adf:b6a3:: with SMTP id j35mr30498378wre.25.1555000523290; Thu, 11 Apr 2019 09:35:23 -0700 (PDT) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="000000000000d0fe1e058643c52d" X-Mailing-List: archive/latest/747365 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/CAMaNm6H-otZbk9nZNThj9WkLpaU6qkbEo+oM2v4B8Kfs=3-8CQ@mail.gmail.com Approved: robomod@news.nic.it Lines: 404 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Thu, 11 Apr 2019 12:35:09 -0400 X-Original-Message-ID: X-Original-References: <10925671283873504605@scdbackup.webframe.org> Xref: csiph.com linux.debian.user:207329 --000000000000d0fe1e058643c52d Content-Type: text/plain; charset="UTF-8" On Fri, Apr 5, 2019, 18:06 Thomas Schmitt wrote: > Hi, > > Chris XX wrote: > > I was trying to Verify the authenticity of Debian CDs on your website, > but I > > don't see instructions that will guide me through the process > > (step-by-step). > > (We are the users. But some Debian Developers are watching, too.) > > Obviously there is a gap between checksum file verification and .iso image > verification. > > Let's first look at the files offered for download: > https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/ > has among others > > SHA512SUMS.sign > SHA512SUMS > debian-9.8.0-amd64-netinst.iso > > > https://www.debian.org/CD/verify > > This publishes the key "fingerprints" by which you can recognize authentic > pairs of SHA512SUMS.sign and SHA512SUMS. > > It points to > https://keyring.debian.org/ > where you probably shall learn how to obtain the keys in question, > namely by the shell commands > > gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D > gpg --keyserver keyring.debian.org --recv-keys 6294BE9B > gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3 > > Experienced users of gpg would know that one can check authenticity by > > gpg --verify SHA512SUMS.sign SHA512SUMS > > which should say something like > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: Good signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. > Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 > BE9B > > The reported fingerprint must be one of the published fingerprints, > or else something is fishy. > Here it is the Debian one of 2011-01-05. I.e. all is well so far. > > If you change some character in SHA512SUMS and run above command again > then you will see > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: BAD signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > > > So you can trust the content of SHA512SUMS, if gpg --verify says it is > good and if the key fingerprint matches one of the Debian fingerprints. > > Now you have to follow the tiny link "faq" at the bottom to > https://www.debian.org/CD/faq/ > where you hop to > https://www.debian.org/CD/faq/#verify > > Between the lines you read that there is a text line in SHA512SUMS which > shows the name of the .iso file which you actually want to verify: > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > More explicite is the hint to use program "sha512sum". A run of > > sha512sum debian-9.8.0-amd64-netinst.iso > > puts out > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > which you should compare with the line in SHA512SUMS. > > Alternatively you could run > > sha512sum --check SHA512SUMS 2>/dev/null > > to get > > debian-9.8.0-amd64-netinst.iso: OK > debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read > debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read > > Or you could download > > https://people.debian.org/~danchev/debian-iso/check_debian_iso > > and run > > chmod u+x ./check_debian_iso > ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso > > to get > > Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through > 'sha512sum' > to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'. > 149504+0 records in > 149504+0 records out > 306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s > Ok: 'debian-9.8.0-amd64-netinst.iso' matches > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > > Now let's see what happens if a single byte is altered in the .iso > > dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511 > of=debian-9.8.0-amd64-netinst.iso > > Now the proposed verifyier runs yield: > > > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > debian-9.8.0-amd64-netinst.iso > > which does obviously not match the line in SHA512SUMS, or > > debian-9.8.0-amd64-netinst.iso: FAILED > ... > > or > > ... > Found: > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > Expected: > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > So you know that the checksumers really detect nearly all damages of > debian-9.8.0-amd64-netinst.iso. > > -------------------------------------------------------------------------- > > @ Steve McIntyre (maintainer of debian-cd): > > Do you agree with the instructions above ? > > Is there a consolidated wiki page with such instructions which i failed > to find ? If not: shall we make such a page ? > > > Have a nice day :) > > Thomas > Thomas, thank you for posting this. It is a good "walk-through" of the verification process. Unfortunately, proper verification can seem too complicated for some users, especially newer ones. So often they just: sha512 sum debian-9.8.0-amd64-netinst.iso say, "looks about the same", and call it a day. Hopefully this will help someone. Thanks again. --000000000000d0fe1e058643c52d Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable


On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <= ;scdbackup@gmx.net> wrote:
<= /div>
Hi,

Chris XX wrote:
> I was trying to Verify the authenticity of Debian CDs on your website,= but I
> don't see instructions that will guide me through the process
> (step-by-step).

(We are the users. But some Debian Developers are watching, too.)

Obviously there is a gap between checksum file verification and .iso image<= br> verification.

Let's first look at the files offered for download:
=C2=A0 https://cdimage.debian.o= rg/debian-cd/current/amd64/iso-cd/
has among others

=C2=A0 SHA512SUMS.sign
=C2=A0 SHA512SUMS
=C2=A0 debian-9.8.0-amd64-netinst.iso

> https://www.debian.org/CD/verify

This publishes the key "fingerprints" by which you can recognize = authentic
pairs of SHA512SUMS.sign and SHA512SUMS.

It points to
=C2=A0 https://keyring.debian.org/
where you probably shall learn how to obtain the keys in question,
namely by the shell commands

=C2=A0 gpg --keyserver keyring.debian.org --recv-keys 64E6EA= 7D
=C2=A0 gpg --keyserver keyring.debian.org --recv-keys 6294BE= 9B
=C2=A0 gpg --keyserver keyring.debian.org --recv-keys 09EA8A= C3

Experienced users of gpg would know that one can check authenticity by

=C2=A0 gpg --verify SHA512SUMS.sign SHA512SUMS

which should say something like

=C2=A0 gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID= 6294BE9B
=C2=A0 gpg: Good signature from "Debian CD signing key <deb= ian-cd@lists.debian.org>"
=C2=A0 gpg: WARNING: This key is not certified with a trusted signature! =C2=A0 gpg:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 There is no indication that t= he signature belongs to the owner.
=C2=A0 Primary key fingerprint: DF9B 9C49 EAA9 2984 3258=C2=A0 9D76 DA87 E8= 0D 6294 BE9B

The reported fingerprint must be one of the published fingerprints,
or else something is fishy.
Here it is the Debian one of 2011-01-05. I.e. all is well so far.

If you change some character in SHA512SUMS and run above command again
then you will see

=C2=A0 gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID= 6294BE9B
=C2=A0 gpg: BAD signature from "Debian CD signing key <debi= an-cd@lists.debian.org>"


So you can trust the content of SHA512SUMS, if gpg --verify says it is
good and if the key fingerprint matches one of the Debian fingerprints.

Now you have to follow the tiny link "faq" at the bottom to
=C2=A0 https://www.debian.org/CD/faq/
where you hop to
=C2=A0 https://www.debian.org/CD/faq/#verify

Between the lines you read that there is a text line in SHA512SUMS which shows the name of the .iso file which you actually want to verify:

=C2=A0 cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4= b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245=C2=A0 debian-9= .8.0-amd64-netinst.iso

More explicite is the hint to use program "sha512sum". A run of
=C2=A0 sha512sum debian-9.8.0-amd64-netinst.iso

puts out

=C2=A0 cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4= b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245=C2=A0 debian-9= .8.0-amd64-netinst.iso

which you should compare with the line in SHA512SUMS.

Alternatively you could run

=C2=A0 sha512sum --check SHA512SUMS 2>/dev/null

to get

=C2=A0 debian-9.8.0-amd64-netinst.iso: OK
=C2=A0 debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read
=C2=A0 debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read

Or you could download

=C2=A0 https://people.debia= n.org/~danchev/debian-iso/check_debian_iso

and run

=C2=A0 chmod u+x ./check_debian_iso
=C2=A0 ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso

to get

=C2=A0 Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' thr= ough 'sha512sum'
=C2=A0 to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'= ;.
=C2=A0 149504+0 records in
=C2=A0 149504+0 records out
=C2=A0 306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s
=C2=A0 Ok: 'debian-9.8.0-amd64-netinst.iso' matches 'debian-9.8= .0-amd64-netinst.iso' in 'SHA512SUMS'


Now let's see what happens if a single byte is altered in the .iso

=C2=A0 dd if=3D/dev/zero bs=3D1 count=3D1 conv=3Dnotrunc seek=3D511 of=3Dde= bian-9.8.0-amd64-netinst.iso

Now the proposed verifyier runs yield:

=C2=A0 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbe= b4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229=C2=A0 debian-9= .8.0-amd64-netinst.iso

which does obviously not match the line in SHA512SUMS, or

=C2=A0 debian-9.8.0-amd64-netinst.iso: FAILED
=C2=A0 ...

or

=C2=A0 ...
=C2=A0 Found:=C2=A0 =C2=A0 =C2=A00b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9= b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f7= 13fa22ff229
=C2=A0 Expected:=C2=A0 cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556= d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a0524= 5
=C2=A0 MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs = from 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'

So you know that the checksumers really detect nearly all damages of
debian-9.8.0-amd64-netinst.iso.

--------------------------------------------------------------------------<= br>
@ Steve McIntyre (maintainer of debian-cd):

Do you agree with the instructions above ?

Is there a consolidated wiki page with such instructions which i failed
to find ? If not: shall we make such a page ?


Have a nice day :)

Thomas

=
Thomas, thank you for posting this.

It is a good "walk-through&quo= t; of the verification process. Unfortunately, proper verification can seem= too complicated for some users, especially newer ones.=C2=A0 So often they= just:

sha512 sum=C2=A0<= span style=3D"font-family:sans-serif">debian-9.8.0-amd64-netinst.iso=C2=A0

say, "looks about the same", and call it a day.<= /span>

Hopeful= ly this will help someone.=C2=A0

Thanks again.

--000000000000d0fe1e058643c52d--