Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #270925 > unrolled thread
| Started by | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| First post | 2024-07-08 22:00 +0200 |
| Last post | 2024-07-08 22:00 +0200 |
| Articles | 1 — 1 participant |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: General questions "Thomas Schmitt" <scdbackup@gmx.net> - 2024-07-08 22:00 +0200
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2024-07-08 22:00 +0200 |
| Subject | Re: General questions |
| Message-ID | <IY2GJ-KB3-3@gated-at.bofh.it> |
Hi, cybertatoka@gmail.com wrote: > 2.2. I have done then: gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS > 2.3. Then I have got next info: Signed was made in 30 june 2024 > And RSA key: DF9B9C49EAA9298432589D76DA87E80D6294BE9B > I have compared 2011 's key and mine and they are the same. The key string looks good, indeed. > But is it a good idea to do that? Or do I need to download the open key and > then compare them? It would suffice for me. If you know more ways to verify that the signature belongs to Debian, then apply them. Just to be sure. > And is verification with SHA512SUMS.sign and SHA512SUMS enough? Should I do > the same actions with SHA216SUMS.sign and SHA216SUMS? It is general belief that faking a SHA-512 checksum is not feasible, currently. Faking both, SHA-512 and SHA-256 would be even more difficult. So check both and raise loud alarm if one matches and the other does not. Have a nice day :) Thomas
Back to top | Article view | linux.debian.user
csiph-web