Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #270914 > unrolled thread

Re: General questions

Started by"Thomas Schmitt" <scdbackup@gmx.net>
First post2024-07-08 20:10 +0200
Last post2024-07-11 15:50 +0200
Articles 17 — 9 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: General questions "Thomas Schmitt" <scdbackup@gmx.net> - 2024-07-08 20:10 +0200
    Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-08 21:20 +0200
      Re: General questions Andy Smith <andy@strugglers.net> - 2024-07-08 23:30 +0200
        Re: General questions gene heskett <gheskett@shentel.net> - 2024-07-09 00:10 +0200
          Re: General questions "Andrew M.A. Cater" <amacater@einval.com> - 2024-07-09 01:10 +0200
            Re: General questions gene heskett <gheskett@shentel.net> - 2024-07-09 01:20 +0200
              Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 00:10 +0200
                Re: General questions Lee <ler762@gmail.com> - 2024-07-11 01:10 +0200
                  Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 13:50 +0200
                    Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 14:00 +0200
                      Re: General questions Franco Martelli <martellif67@gmail.com> - 2024-07-11 21:30 +0200
                      Re: General questions Lee <ler762@gmail.com> - 2024-07-11 22:00 +0200
                    Re: General questions Greg Wooledge <greg@wooledge.org> - 2024-07-11 14:00 +0200
                      Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 14:30 +0200
                        Re: General questions "Thomas Schmitt" <scdbackup@gmx.net> - 2024-07-11 14:40 +0200
                        Re: General questions Greg Wooledge <greg@wooledge.org> - 2024-07-11 14:40 +0200
                          Re: General questions Dan Purgert <dan@djph.net> - 2024-07-11 15:50 +0200

#270914 — Re: General questions

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2024-07-08 20:10 +0200
SubjectRe: General questions
Message-ID<IY0Yh-JLV-3@gated-at.bofh.it>
Hi,

cybertatoka@gmail.com wrote:
> 2. How to check Debian Image Authentication?
> Is checksum verification (sha216sum, sha512sum) enough?

Only if you are trusting the site from where you downloaded the ISO.
In that case you'd use the checksums in the files SHA256SUMS and
SHA512SUMS as mere control whether the download delivered what the server
operators intended.


> Should I verify with GPG?

The signatures in the files SHA256SUMS.sign and SHA512SUMS.sign verify that
the checksums in SHA256SUMS and SHA512SUMS are authorized by the Debian
developers who are in charge of image production.

Verify them by e.g.

  gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS

and look out for the text,

  gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>"
  ...
  Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

First occuruence of this fingerprint in my mailbox is Oct 10 2015.

On
  https://www.debian.org/CD/verify
there are two more valid keys published which would yield:

  gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>"
  Primary key fingerprint:  1046 0DAD 7616 5AD8 1FBC  0CE9 9880 21A9 64E6 EA7D

  gpg: Good signature from "Debian Testing CDs Automatic Signing Key <debian-cd@lists.debian.org>"
  Primary key fingerprint: F41D 3034 2F35 4669 5F65  C669 4246 8F40 09EA 8AC3

Both have their first occurence in my mailbox at Feb 16 2020.

If you see one of these texts, then you may assume the checksum files to
be valid (or the fingerprints to be undetected falsifications since years).
But if you see deviations in the fingerprint lines then this would be very
suspicious.


Have a nice day :)

Thomas

[toc] | [next] | [standalone]


#270947

From타토카 <cybertatoka@gmail.com>
Date2024-07-08 21:20 +0200
Message-ID<IY242-Ko7-5@gated-at.bofh.it>
In reply to#270914

[Multipart message — attachments visible in raw view] — view raw

Thank you all for your answers.
1. But I mean subscriptions like this "debian-user":) But I really like
your answers about Debian's freedom. I think it is useful information.
Thanks.
2. I just have verified GPG's keys manually: https://keyring.debian.org/
    2.1. I have downloaded SHA512 SUMS.sign SHA512SUMS from
https://cdimage.debian.org/debian-cd/current/amd64/bt-cd/
    2.2. I have done then: gpg --keyserver keyring.debian.org --verify
SHA512SUMS.sign SHA512SUMS
    2.3. Then I have got next info: Signed was made in 30 june 2024
    And RSA key: DF9B9C49EAA9298432589D76DA87E80D6294BE9B
I have compared 2011 's key and mine and they are the same.
But is it a good idea to do that? Or do I need to download the open key and
then compare them?
And is verification with SHA512SUMS.sign and SHA512SUMS enough? Should I do
the same actions with SHA216SUMS.sign and SHA216SUMS?

On Mon, Jul 8, 2024 at 11:00 PM Thomas Schmitt <scdbackup@gmx.net> wrote:

> Hi,
>
> cybertatoka@gmail.com wrote:
> > 2. How to check Debian Image Authentication?
> > Is checksum verification (sha216sum, sha512sum) enough?
>
> Only if you are trusting the site from where you downloaded the ISO.
> In that case you'd use the checksums in the files SHA256SUMS and
> SHA512SUMS as mere control whether the download delivered what the server
> operators intended.
>
>
> > Should I verify with GPG?
>
> The signatures in the files SHA256SUMS.sign and SHA512SUMS.sign verify that
> the checksums in SHA256SUMS and SHA512SUMS are authorized by the Debian
> developers who are in charge of image production.
>
> Verify them by e.g.
>
>   gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS
>
> and look out for the text,
>
>   gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>   ...
>   Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
> BE9B
>
> First occuruence of this fingerprint in my mailbox is Oct 10 2015.
>
> On
>   https://www.debian.org/CD/verify
> there are two more valid keys published which would yield:
>
>   gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>   Primary key fingerprint:  1046 0DAD 7616 5AD8 1FBC  0CE9 9880 21A9 64E6
> EA7D
>
>   gpg: Good signature from "Debian Testing CDs Automatic Signing Key <
> debian-cd@lists.debian.org>"
>   Primary key fingerprint: F41D 3034 2F35 4669 5F65  C669 4246 8F40 09EA
> 8AC3
>
> Both have their first occurence in my mailbox at Feb 16 2020.
>
> If you see one of these texts, then you may assume the checksum files to
> be valid (or the fingerprints to be undetected falsifications since years).
> But if you see deviations in the fingerprint lines then this would be very
> suspicious.
>
>
> Have a nice day :)
>
> Thomas
>
>

[toc] | [prev] | [next] | [standalone]


#270949

FromAndy Smith <andy@strugglers.net>
Date2024-07-08 23:30 +0200
Message-ID<IY45Q-LzE-1@gated-at.bofh.it>
In reply to#270947
Hi,

On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote:
> I mean subscriptions like this "debian-user"

The only cost associated with this mailing list is your sanity.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#270952

Fromgene heskett <gheskett@shentel.net>
Date2024-07-09 00:10 +0200
Message-ID<IY4Ix-M4z-3@gated-at.bofh.it>
In reply to#270949
On 7/8/24 17:20, Andy Smith wrote:
> Hi,
> 
> On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote:
>> I mean subscriptions like this "debian-user"
> 
> The only cost associated with this mailing list is your sanity.
> 
+1, Andy. Some of us get downright upset with the Karens that think they 
run this all volunteer show. I've unfortunately come to the conclusion 
they are best ignored. Generally, they don't seem to be members of a 
civil society, or to be able to learn how to treat their fellow man. 
Your monitoring, and howto corrections are much appreciated, thank you.

> Thanks,
> Andy
> 

Cheers, Gene Heskett, CET.
-- 
"There are four boxes to be used in defense of liberty:
  soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
  - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#270953

From"Andrew M.A. Cater" <amacater@einval.com>
Date2024-07-09 01:10 +0200
Message-ID<IY5EB-MCP-1@gated-at.bofh.it>
In reply to#270952
On Mon, Jul 08, 2024 at 06:08:49PM -0400, gene heskett wrote:
> On 7/8/24 17:20, Andy Smith wrote:
> > Hi,
> > 
> > On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote:
> > > I mean subscriptions like this "debian-user"
> > 
> > The only cost associated with this mailing list is your sanity.
> > 
> +1, Andy. Some of us get downright upset with the Karens that think they run
> this all volunteer show. I've unfortunately come to the conclusion they are
> best ignored. Generally, they don't seem to be members of a civil society,
> or to be able to learn how to treat their fellow man. Your monitoring, and
> howto corrections are much appreciated, thank you.
> 
> > Thanks,
> > Andy
> > 
> 

All contributions by any Andy gratefully received on this list. There
are also all sorts of people contributing to - and reading - this list.
Sometimes, even the worst of the passers by and trolls improve.

Please don't stoop to characterising others too readily as you might 
dissuade somebody from contributing who could be really valuable.

All the very best, as ever,

Andy
(amacater@debian.org)

> Cheers, Gene Heskett, CET.
> -- 
> "There are four boxes to be used in defense of liberty:
>  soap, ballot, jury, and ammo. Please use in that order."
> -Ed Howdershelt (Author, 1940)
> If we desire respect for the law, we must first make the law respectable.
>  - Louis D. Brandeis
> 

[toc] | [prev] | [next] | [standalone]


#270954

Fromgene heskett <gheskett@shentel.net>
Date2024-07-09 01:20 +0200
Message-ID<IY5Oh-MFO-1@gated-at.bofh.it>
In reply to#270953
On 7/8/24 19:02, Andrew M.A. Cater wrote:
> On Mon, Jul 08, 2024 at 06:08:49PM -0400, gene heskett wrote:
>> On 7/8/24 17:20, Andy Smith wrote:
>>> Hi,
>>>
>>> On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote:
>>>> I mean subscriptions like this "debian-user"
>>>
>>> The only cost associated with this mailing list is your sanity.
>>>
>> +1, Andy. Some of us get downright upset with the Karens that think they run
>> this all volunteer show. I've unfortunately come to the conclusion they are
>> best ignored. Generally, they don't seem to be members of a civil society,
>> or to be able to learn how to treat their fellow man. Your monitoring, and
>> howto corrections are much appreciated, thank you.
>>
>>> Thanks,
>>> Andy
>>>
>>
> 
> All contributions by any Andy gratefully received on this list. There
> are also all sorts of people contributing to - and reading - this list.
> Sometimes, even the worst of the passers by and trolls improve.
> 
> Please don't stoop to characterising others too readily as you might
> dissuade somebody from contributing who could be really valuable.

All quite true Andy. But you may have noted that I only speak up from 
personal experience from having done it myself, not always in the 
approved way.

> All the very best, as ever,
> 
> Andy
> (amacater@debian.org)

Take care & stay well, Andy.


>> Cheers, Gene Heskett, CET.
>> -- 
>> "There are four boxes to be used in defense of liberty:
>>   soap, ballot, jury, and ammo. Please use in that order."
>> -Ed Howdershelt (Author, 1940)
>> If we desire respect for the law, we must first make the law respectable.
>>   - Louis D. Brandeis
>>
> 
> .

Cheers, Gene Heskett, CET.
-- 
"There are four boxes to be used in defense of liberty:
  soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
  - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#271049

From타토카 <cybertatoka@gmail.com>
Date2024-07-11 00:10 +0200
Message-ID<IYNFE-1dMg-21@gated-at.bofh.it>
In reply to#270954

[Multipart message — attachments visible in raw view] — view raw

Hello, dear Debian Community.

I just wanted to check a key with GPG.

I have found this on https://www.debian.org/CD/verify:

pub   rsa4096/DA87E80D6294BE9B 2011-01-05 [SC]

Key fingerprint = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

uid                  Debian CD signing key <debian-cd@lists.debian.org>


How can I download this key for GPG checking? Can I do next:

gpg --keyserver keyring.debian.org --recv-keys DA87E80D6294BE9B


If not, can you give an advice how to do it right?

[toc] | [prev] | [next] | [standalone]


#271054

FromLee <ler762@gmail.com>
Date2024-07-11 01:10 +0200
Message-ID<IYOBH-1euu-1@gated-at.bofh.it>
In reply to#271049
On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote:
>
> Hello, dear Debian Community.
>
> I just wanted to check a key with GPG.
>
> I have found this on https://www.debian.org/CD/verify:
>
> pub   rsa4096/DA87E80D6294BE9B 2011-01-05 [SC]
>
> Key fingerprint = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B
>
> uid                  Debian CD signing key <debian-cd@lists.debian.org>
>
>
> How can I download this key for GPG checking?

Click on the link, that takes you to
  https://www.debian.org/CD/key-DA87E80D6294BE9B.txt
and save the file.  Then gpg --import it

$ gpg --import key-DA87E80D6294BE9B.txt
gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
<debian-cd@lists.debian.org>" imported
gpg: Total number processed: 1
gpg:               imported: 1
gpg: no ultimately trusted keys found

hrmmm... 64 signatures not checked due to missing keys due to missing
keys doesn't look good, but you've got the key now.

I checked by going to
http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got
the SHA512SUMS and SHA512SUMS.sign files.
Verify them by

$ gpg --verify SHA512SUMS.sign SHA512SUMS
gpg: Signature made Sat Jun 29 16:50:24 2024 EDT
gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: Good signature from "Debian CD signing key
<debian-cd@lists.debian.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

so the contents of SHA512SUMS are trustworthy.  Or as trustworthy as I
can verify.. somebody else hopefully knows how to get all the missing
keys and mark the DA87E80D6294BE9B key as trusted.

and for whatever it's worth, I use these aliases:
$ alias | grep sha
alias sha1='/usr/bin/openssl dgst -sha1 '
alias sha256='/usr/bin/openssl dgst -sha256 '
alias sha512='/usr/bin/openssl dgst -sha512 '

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#271072

From타토카 <cybertatoka@gmail.com>
Date2024-07-11 13:50 +0200
Message-ID<IZ0tb-1mc8-1@gated-at.bofh.it>
In reply to#271054

[Multipart message — attachments visible in raw view] — view raw

Why 64 signatures not checked and no ultimately trusted keys found here:
$ gpg --import key-DA87E80D6294BE9B.txt
gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
<debian-cd@lists.debian.org>" imported
gpg: Total number processed: 1
gpg:               imported: 1
gpg: no ultimately trusted keys found

And this:
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the
owner.

This is weird. Why Fedora does not have this, but Debian does.

And can you explain to me what is it, please?

On Thu, Jul 11, 2024 at 4:00 AM Lee <ler762@gmail.com> wrote:

> On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote:
> >
> > Hello, dear Debian Community.
> >
> > I just wanted to check a key with GPG.
> >
> > I have found this on https://www.debian.org/CD/verify:
> >
> > pub   rsa4096/DA87E80D6294BE9B 2011-01-05 [SC]
> >
> > Key fingerprint = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B
> >
> > uid                  Debian CD signing key <debian-cd@lists.debian.org>
> >
> >
> > How can I download this key for GPG checking?
>
> Click on the link, that takes you to
>   https://www.debian.org/CD/key-DA87E80D6294BE9B.txt
> and save the file.  Then gpg --import it
>
> $ gpg --import key-DA87E80D6294BE9B.txt
> gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
> gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
> <debian-cd@lists.debian.org>" imported
> gpg: Total number processed: 1
> gpg:               imported: 1
> gpg: no ultimately trusted keys found
>
> hrmmm... 64 signatures not checked due to missing keys due to missing
> keys doesn't look good, but you've got the key now.
>
> I checked by going to
> http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got
> the SHA512SUMS and SHA512SUMS.sign files.
> Verify them by
>
> $ gpg --verify SHA512SUMS.sign SHA512SUMS
> gpg: Signature made Sat Jun 29 16:50:24 2024 EDT
> gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
> gpg: Good signature from "Debian CD signing key
> <debian-cd@lists.debian.org>" [unknown]
> gpg: WARNING: This key is not certified with a trusted signature!
> gpg:          There is no indication that the signature belongs to the
> owner.
> Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B
>
> so the contents of SHA512SUMS are trustworthy.  Or as trustworthy as I
> can verify.. somebody else hopefully knows how to get all the missing
> keys and mark the DA87E80D6294BE9B key as trusted.
>
> and for whatever it's worth, I use these aliases:
> $ alias | grep sha
> alias sha1='/usr/bin/openssl dgst -sha1 '
> alias sha256='/usr/bin/openssl dgst -sha256 '
> alias sha512='/usr/bin/openssl dgst -sha512 '
>
> Regards,
> Lee
>

[toc] | [prev] | [next] | [standalone]


#271073

From타토카 <cybertatoka@gmail.com>
Date2024-07-11 14:00 +0200
Message-ID<IZ0CR-1mgp-3@gated-at.bofh.it>
In reply to#271072

[Multipart message — attachments visible in raw view] — view raw

And can you explain to me what is it, please? *

$ alias | grep sha
alias sha1='/usr/bin/openssl dgst -sha1 '
alias sha256='/usr/bin/openssl dgst -sha256 '
alias sha512='/usr/bin/openssl dgst -sha512 '

On Thu, Jul 11, 2024 at 4:47 PM 타토카 <cybertatoka@gmail.com> wrote:

> Why 64 signatures not checked and no ultimately trusted keys found here:
> $ gpg --import key-DA87E80D6294BE9B.txt
> gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
> gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
> <debian-cd@lists.debian.org>" imported
> gpg: Total number processed: 1
> gpg:               imported: 1
> gpg: no ultimately trusted keys found
>
> And this:
> gpg: WARNING: This key is not certified with a trusted signature!
> gpg:          There is no indication that the signature belongs to the
> owner.
>
> This is weird. Why Fedora does not have this, but Debian does.
>
> And can you explain to me what is it, please?
>
> On Thu, Jul 11, 2024 at 4:00 AM Lee <ler762@gmail.com> wrote:
>
>> On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote:
>> >
>> > Hello, dear Debian Community.
>> >
>> > I just wanted to check a key with GPG.
>> >
>> > I have found this on https://www.debian.org/CD/verify:
>> >
>> > pub   rsa4096/DA87E80D6294BE9B 2011-01-05 [SC]
>> >
>> > Key fingerprint = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B
>> >
>> > uid                  Debian CD signing key <debian-cd@lists.debian.org>
>> >
>> >
>> > How can I download this key for GPG checking?
>>
>> Click on the link, that takes you to
>>   https://www.debian.org/CD/key-DA87E80D6294BE9B.txt
>> and save the file.  Then gpg --import it
>>
>> $ gpg --import key-DA87E80D6294BE9B.txt
>> gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
>> gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
>> <debian-cd@lists.debian.org>" imported
>> gpg: Total number processed: 1
>> gpg:               imported: 1
>> gpg: no ultimately trusted keys found
>>
>> hrmmm... 64 signatures not checked due to missing keys due to missing
>> keys doesn't look good, but you've got the key now.
>>
>> I checked by going to
>> http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got
>> the SHA512SUMS and SHA512SUMS.sign files.
>> Verify them by
>>
>> $ gpg --verify SHA512SUMS.sign SHA512SUMS
>> gpg: Signature made Sat Jun 29 16:50:24 2024 EDT
>> gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
>> gpg: Good signature from "Debian CD signing key
>> <debian-cd@lists.debian.org>" [unknown]
>> gpg: WARNING: This key is not certified with a trusted signature!
>> gpg:          There is no indication that the signature belongs to the
>> owner.
>> Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
>> BE9B
>>
>> so the contents of SHA512SUMS are trustworthy.  Or as trustworthy as I
>> can verify.. somebody else hopefully knows how to get all the missing
>> keys and mark the DA87E80D6294BE9B key as trusted.
>>
>> and for whatever it's worth, I use these aliases:
>> $ alias | grep sha
>> alias sha1='/usr/bin/openssl dgst -sha1 '
>> alias sha256='/usr/bin/openssl dgst -sha256 '
>> alias sha512='/usr/bin/openssl dgst -sha512 '
>>
>> Regards,
>> Lee
>>
>

[toc] | [prev] | [next] | [standalone]


#271081

FromFranco Martelli <martellif67@gmail.com>
Date2024-07-11 21:30 +0200
Message-ID<IZ7Eo-1qDQ-9@gated-at.bofh.it>
In reply to#271073
On 11/07/24 at 13:55, 타토카 wrote:
> And can you explain to me what is it, please? *
> 
> $ alias | grep sha
> alias sha1='/usr/bin/openssl dgst -sha1 '
> alias sha256='/usr/bin/openssl dgst -sha256 '
> alias sha512='/usr/bin/openssl dgst -sha512 '

Since you are asking this question maybe you don't know that after 
verified the authenticity of SHA512SUMS.sign SHA512SUMS files you must 
use the file SHA512SUMS to verify the authenticity of the .iso files you 
will download.

If you open SHA512SUMS in an editor you see a list of checksum that they 
belong to respective .iso or .torrent files.

Recently I downloaded the "debian-12.6.0-amd64-DVD-1.iso" iso image 
using a .torrent file. After downloaded the .torrent file place it 
together SHA512SUMS in the same directory, then verify the authenticity 
with the command:

$ sha512sum --ignore-missing -c SHA512SUMS
debian-12.6.0-amd64-DVD-1.iso.torrent: OK

Now you are ready to download the .iso, open the .torrent file in your 
favorite Torrent client and start the download, then check the 
authenticity of the .iso with exactly the same command:

$ sha512sum --ignore-missing -c SHA512SUMS
debian-12.6.0-amd64-DVD-1.iso: OK

This step might take a while, so be patient, after done that you are 
ready to burn a DVD, copy the .iso to an USB key, install to a virtual 
machine… but this is another story ^_^

Cheers,
-- 
Franco Martelli

[toc] | [prev] | [next] | [standalone]


#271082

FromLee <ler762@gmail.com>
Date2024-07-11 22:00 +0200
Message-ID<IZ87n-1qNb-1@gated-at.bofh.it>
In reply to#271073
On Thu, Jul 11, 2024 at 7:55 AM 타토카 <cybertatoka@gmail.com> wrote:
>
> And can you explain to me what is it, please? *
>
> $ alias | grep sha
> alias sha1='/usr/bin/openssl dgst -sha1 '
> alias sha256='/usr/bin/openssl dgst -sha256 '
> alias sha512='/usr/bin/openssl dgst -sha512 '

It's a way of getting sha sums for a file.  I've been carrying those
in my .bashrc file for ages.. I don't remember if I didn't know about
the sha1sum program or it didn't exist in cygwin at the time, but I
found a method that worked and quit looking.  By now it's "muscle
memory" -- like returning from vacation and not being able to remember
your password, but go down to the cafeteria, get a cup of coffee,
return to your desk, turn your PC on and enter your password without
thinking.  I found a method that worked and don't think about it any
more.  You probably should use the sha1sum, sha256sum, sha512sum
programs though - if only to reduce confusion when you're talking to
other people :)

Regards
Lee

[toc] | [prev] | [next] | [standalone]


#271074

FromGreg Wooledge <greg@wooledge.org>
Date2024-07-11 14:00 +0200
Message-ID<IZ0CR-1mgp-9@gated-at.bofh.it>
In reply to#271072
On Thu, Jul 11, 2024 at 16:47:45 +0500, 타토카 wrote:
> Why 64 signatures not checked and no ultimately trusted keys found here:
> $ gpg --import key-DA87E80D6294BE9B.txt
> gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
> gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
> <debian-cd@lists.debian.org>" imported
> gpg: Total number processed: 1
> gpg:               imported: 1
> gpg: no ultimately trusted keys found
> 
> And this:
> gpg: WARNING: This key is not certified with a trusted signature!
> gpg:          There is no indication that the signature belongs to the
> owner.

Because you haven't established a chain of trust from yourself to any
of the signatures.

You've downloaded this key from the Internet.  And it's signed by 64
other keys.  That's all you know.  You have no idea whether any of those
64 signing keys are trustworthy.

At some point, you have to say "This is good enough."  And then you move
on with your life, either installing Debian from the image that you have,
or not.

You've already done far more verification than most people do.

[toc] | [prev] | [next] | [standalone]


#271075

From타토카 <cybertatoka@gmail.com>
Date2024-07-11 14:30 +0200
Message-ID<IZ15T-1mFL-1@gated-at.bofh.it>
In reply to#271074

[Multipart message — attachments visible in raw view] — view raw

Ok, I think this is really enough for verification ( Maybe (^_^) ).
But, what do you mean: "Because you haven't established a chain of trust
from yourself to any of the signatures."
Is it only for Debian developers? And is it very important?

On Thu, Jul 11, 2024 at 4:58 PM Greg Wooledge <greg@wooledge.org> wrote:

> On Thu, Jul 11, 2024 at 16:47:45 +0500, 타토카 wrote:
> > Why 64 signatures not checked and no ultimately trusted keys found here:
> > $ gpg --import key-DA87E80D6294BE9B.txt
> > gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys
> > gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
> > <debian-cd@lists.debian.org>" imported
> > gpg: Total number processed: 1
> > gpg:               imported: 1
> > gpg: no ultimately trusted keys found
> >
> > And this:
> > gpg: WARNING: This key is not certified with a trusted signature!
> > gpg:          There is no indication that the signature belongs to the
> > owner.
>
> Because you haven't established a chain of trust from yourself to any
> of the signatures.
>
> You've downloaded this key from the Internet.  And it's signed by 64
> other keys.  That's all you know.  You have no idea whether any of those
> 64 signing keys are trustworthy.
>
> At some point, you have to say "This is good enough."  And then you move
> on with your life, either installing Debian from the image that you have,
> or not.
>
> You've already done far more verification than most people do.
>
>

[toc] | [prev] | [next] | [standalone]


#271076

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2024-07-11 14:40 +0200
Message-ID<IZ1fz-1mIV-9@gated-at.bofh.it>
In reply to#271075
Hi,

cybertatoka@gmail.com wrote:
> gpg: WARNING: This key is not certified with a trusted signature!

That's normal. The concept of a "web of trust" suffers from the fact
that most people which i know good enough to trust them in general
have no idea of PGP and thus are not really trustworthy in special.
  https://en.wikipedia.org/wiki/Web_of_trust

The best verification you can get outside the web of trust is the
key fingerprint which must match one of the published fingerprints on
  https://www.debian.org/CD/verify
I deem them trustworthy because they did not change in years.

(Cryptographers might object that old keys are poor keys. But they will
also be right with telling you that cryptography is a minefield and thus
amateurs like us should stay away from it.)


> And can you explain to me what is it, please?
> $ alias | grep sha
> alias sha1='/usr/bin/openssl dgst -sha1 '
> alias sha256='/usr/bin/openssl dgst -sha256 '
> alias sha512='/usr/bin/openssl dgst -sha512 '

Shell commands "sha1", "sha256", and "sha512" were somewhere defined to
actually be runs of program /usr/bin/openssl with the checksum algorithms
given by the command names.

Usually people get told to use shell commands "sha256sum" and "sha512sum"
which are supposed to run the programs /usr/bin/sha256sum and
/usr/bin/sha512sum from package "coreutils".

In order to find out from where the "alias" definitions stem, you will
have to check the startup scripts of your shell. Like ~/.bashrc .


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#271077

FromGreg Wooledge <greg@wooledge.org>
Date2024-07-11 14:40 +0200
Message-ID<IZ1fz-1mIV-11@gated-at.bofh.it>
In reply to#271075
On Thu, Jul 11, 2024 at 17:23:43 +0500, 타토카 wrote:
> But, what do you mean: "Because you haven't established a chain of trust
> from yourself to any of the signatures."

Imagine someone walks up to you on the street and hands you a contract,
which is signed by someone you've never heard of.

You don't know the guy who gave you the contract.  You've never seen him
before.  So, you don't trust him.

You can do a little bit of research on the person whose signature is on
the contract.  Maybe she's famous.  You look her up on the Internet, and
it turns out that she's well known in certain circles.  If her signature
is on this contract, then the contract is probably worth something.

But how do you know whether this is really her signature, or a forgery?

If you knew her in person, you could go to her office, ask her to sign
something in your presence, and compare her signature to the one you see
on the contract.

But you don't know her in person.  She lives really far away, and she's
too important and too busy to want to spend a lot of time signing blank
pieces of paper for people like you anyway.

But maybe you know someone who knows her.  Your lawyer friend -- maybe
he's worked with her before.  He might know what her signature looks
like.  He might be able to tell you whether the signature on the contract
is valid.

So, you go to your lawyer friend, and you show him the contract, and
he says "Yeah, that looks legit."

Now you know what her signature looks like, or at least you've got
verification from a source that you trust.

> Is it only for Debian developers? And is it very important?

In theory, anybody can attend a key signing party, and get in-person
verification of various GPG keys.  Once you've got a few keys from
people that you trust, your web of trust expands.

If you've got a trusted key from Joe Smith, and Joe Smith says he
trusts a key belonging to Sara Jones, and Sara Jones says she trusts
the Debian signing key that you're trying to verify, then you have a
chain of trust from yourself, to Joe, to Sara, to the Debian key.

In practice, very few people do this, because it's a LOT of effort.

[toc] | [prev] | [next] | [standalone]


#271078

FromDan Purgert <dan@djph.net>
Date2024-07-11 15:50 +0200
Message-ID<IZ2lj-1nlp-1@gated-at.bofh.it>
In reply to#271077

[Multipart message — attachments visible in raw view] — view raw

On Jul 11, 2024, Greg Wooledge wrote:
> On Thu, Jul 11, 2024 at 17:23:43 +0500, 타토카 wrote:
> > But, what do you mean: "Because you haven't established a chain of trust
> > from yourself to any of the signatures."
> 
> Imagine someone walks up to you on the street and hands you a contract,
> which is signed by someone you've never heard of.
> 
> You don't know the guy who gave you the contract.  You've never seen him
> before.  So, you don't trust him. [...]

I always liked the analogy of schoolwork / notes.

Say you missed last Friday's class, and you need the notes (where "the
notes" correspond to "the pgp key in question").

Scenario A: "untrusted" ("website with a link / posted fingerprint")
You run into someone from class, who you don't really know all that
well, but you do know they answer the professor pretty often (and
correctly at that).  

Scenario B: "web of trust" ("one or more trusted signatures on that key")
Nearly the same as "A", but the other person is a friend-of-a-friend.
You can ask your friend when you meet them for lunch if you can trust
the classmate's notes.

Scenario C: "fully trusted" ("you made the effort to verify the owner")
You ask you best friend since second grade for their notes.  You know
they've been an "A" student since forever, and they take amazing notes.



-- 
|_|O|_| 
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1  E067 6D65 70E5 4CE7 2860

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web