Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #270914 > unrolled thread
| Started by | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| First post | 2024-07-08 20:10 +0200 |
| Last post | 2024-07-11 15:50 +0200 |
| Articles | 17 — 9 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: General questions "Thomas Schmitt" <scdbackup@gmx.net> - 2024-07-08 20:10 +0200
Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-08 21:20 +0200
Re: General questions Andy Smith <andy@strugglers.net> - 2024-07-08 23:30 +0200
Re: General questions gene heskett <gheskett@shentel.net> - 2024-07-09 00:10 +0200
Re: General questions "Andrew M.A. Cater" <amacater@einval.com> - 2024-07-09 01:10 +0200
Re: General questions gene heskett <gheskett@shentel.net> - 2024-07-09 01:20 +0200
Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 00:10 +0200
Re: General questions Lee <ler762@gmail.com> - 2024-07-11 01:10 +0200
Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 13:50 +0200
Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 14:00 +0200
Re: General questions Franco Martelli <martellif67@gmail.com> - 2024-07-11 21:30 +0200
Re: General questions Lee <ler762@gmail.com> - 2024-07-11 22:00 +0200
Re: General questions Greg Wooledge <greg@wooledge.org> - 2024-07-11 14:00 +0200
Re: General questions 타토카 <cybertatoka@gmail.com> - 2024-07-11 14:30 +0200
Re: General questions "Thomas Schmitt" <scdbackup@gmx.net> - 2024-07-11 14:40 +0200
Re: General questions Greg Wooledge <greg@wooledge.org> - 2024-07-11 14:40 +0200
Re: General questions Dan Purgert <dan@djph.net> - 2024-07-11 15:50 +0200
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2024-07-08 20:10 +0200 |
| Subject | Re: General questions |
| Message-ID | <IY0Yh-JLV-3@gated-at.bofh.it> |
Hi, cybertatoka@gmail.com wrote: > 2. How to check Debian Image Authentication? > Is checksum verification (sha216sum, sha512sum) enough? Only if you are trusting the site from where you downloaded the ISO. In that case you'd use the checksums in the files SHA256SUMS and SHA512SUMS as mere control whether the download delivered what the server operators intended. > Should I verify with GPG? The signatures in the files SHA256SUMS.sign and SHA512SUMS.sign verify that the checksums in SHA256SUMS and SHA512SUMS are authorized by the Debian developers who are in charge of image production. Verify them by e.g. gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS and look out for the text, gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" ... Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B First occuruence of this fingerprint in my mailbox is Oct 10 2015. On https://www.debian.org/CD/verify there are two more valid keys published which would yield: gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" Primary key fingerprint: 1046 0DAD 7616 5AD8 1FBC 0CE9 9880 21A9 64E6 EA7D gpg: Good signature from "Debian Testing CDs Automatic Signing Key <debian-cd@lists.debian.org>" Primary key fingerprint: F41D 3034 2F35 4669 5F65 C669 4246 8F40 09EA 8AC3 Both have their first occurence in my mailbox at Feb 16 2020. If you see one of these texts, then you may assume the checksum files to be valid (or the fingerprints to be undetected falsifications since years). But if you see deviations in the fingerprint lines then this would be very suspicious. Have a nice day :) Thomas
[toc] | [next] | [standalone]
| From | 타토카 <cybertatoka@gmail.com> |
|---|---|
| Date | 2024-07-08 21:20 +0200 |
| Message-ID | <IY242-Ko7-5@gated-at.bofh.it> |
| In reply to | #270914 |
[Multipart message — attachments visible in raw view] — view raw
Thank you all for your answers.
1. But I mean subscriptions like this "debian-user":) But I really like
your answers about Debian's freedom. I think it is useful information.
Thanks.
2. I just have verified GPG's keys manually: https://keyring.debian.org/
2.1. I have downloaded SHA512 SUMS.sign SHA512SUMS from
https://cdimage.debian.org/debian-cd/current/amd64/bt-cd/
2.2. I have done then: gpg --keyserver keyring.debian.org --verify
SHA512SUMS.sign SHA512SUMS
2.3. Then I have got next info: Signed was made in 30 june 2024
And RSA key: DF9B9C49EAA9298432589D76DA87E80D6294BE9B
I have compared 2011 's key and mine and they are the same.
But is it a good idea to do that? Or do I need to download the open key and
then compare them?
And is verification with SHA512SUMS.sign and SHA512SUMS enough? Should I do
the same actions with SHA216SUMS.sign and SHA216SUMS?
On Mon, Jul 8, 2024 at 11:00 PM Thomas Schmitt <scdbackup@gmx.net> wrote:
> Hi,
>
> cybertatoka@gmail.com wrote:
> > 2. How to check Debian Image Authentication?
> > Is checksum verification (sha216sum, sha512sum) enough?
>
> Only if you are trusting the site from where you downloaded the ISO.
> In that case you'd use the checksums in the files SHA256SUMS and
> SHA512SUMS as mere control whether the download delivered what the server
> operators intended.
>
>
> > Should I verify with GPG?
>
> The signatures in the files SHA256SUMS.sign and SHA512SUMS.sign verify that
> the checksums in SHA256SUMS and SHA512SUMS are authorized by the Debian
> developers who are in charge of image production.
>
> Verify them by e.g.
>
> gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS
>
> and look out for the text,
>
> gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
> ...
> Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294
> BE9B
>
> First occuruence of this fingerprint in my mailbox is Oct 10 2015.
>
> On
> https://www.debian.org/CD/verify
> there are two more valid keys published which would yield:
>
> gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
> Primary key fingerprint: 1046 0DAD 7616 5AD8 1FBC 0CE9 9880 21A9 64E6
> EA7D
>
> gpg: Good signature from "Debian Testing CDs Automatic Signing Key <
> debian-cd@lists.debian.org>"
> Primary key fingerprint: F41D 3034 2F35 4669 5F65 C669 4246 8F40 09EA
> 8AC3
>
> Both have their first occurence in my mailbox at Feb 16 2020.
>
> If you see one of these texts, then you may assume the checksum files to
> be valid (or the fingerprints to be undetected falsifications since years).
> But if you see deviations in the fingerprint lines then this would be very
> suspicious.
>
>
> Have a nice day :)
>
> Thomas
>
>
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2024-07-08 23:30 +0200 |
| Message-ID | <IY45Q-LzE-1@gated-at.bofh.it> |
| In reply to | #270947 |
Hi, On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote: > I mean subscriptions like this "debian-user" The only cost associated with this mailing list is your sanity. Thanks, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2024-07-09 00:10 +0200 |
| Message-ID | <IY4Ix-M4z-3@gated-at.bofh.it> |
| In reply to | #270949 |
On 7/8/24 17:20, Andy Smith wrote: > Hi, > > On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote: >> I mean subscriptions like this "debian-user" > > The only cost associated with this mailing list is your sanity. > +1, Andy. Some of us get downright upset with the Karens that think they run this all volunteer show. I've unfortunately come to the conclusion they are best ignored. Generally, they don't seem to be members of a civil society, or to be able to learn how to treat their fellow man. Your monitoring, and howto corrections are much appreciated, thank you. > Thanks, > Andy > Cheers, Gene Heskett, CET. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2024-07-09 01:10 +0200 |
| Message-ID | <IY5EB-MCP-1@gated-at.bofh.it> |
| In reply to | #270952 |
On Mon, Jul 08, 2024 at 06:08:49PM -0400, gene heskett wrote: > On 7/8/24 17:20, Andy Smith wrote: > > Hi, > > > > On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote: > > > I mean subscriptions like this "debian-user" > > > > The only cost associated with this mailing list is your sanity. > > > +1, Andy. Some of us get downright upset with the Karens that think they run > this all volunteer show. I've unfortunately come to the conclusion they are > best ignored. Generally, they don't seem to be members of a civil society, > or to be able to learn how to treat their fellow man. Your monitoring, and > howto corrections are much appreciated, thank you. > > > Thanks, > > Andy > > > All contributions by any Andy gratefully received on this list. There are also all sorts of people contributing to - and reading - this list. Sometimes, even the worst of the passers by and trolls improve. Please don't stoop to characterising others too readily as you might dissuade somebody from contributing who could be really valuable. All the very best, as ever, Andy (amacater@debian.org) > Cheers, Gene Heskett, CET. > -- > "There are four boxes to be used in defense of liberty: > soap, ballot, jury, and ammo. Please use in that order." > -Ed Howdershelt (Author, 1940) > If we desire respect for the law, we must first make the law respectable. > - Louis D. Brandeis >
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2024-07-09 01:20 +0200 |
| Message-ID | <IY5Oh-MFO-1@gated-at.bofh.it> |
| In reply to | #270953 |
On 7/8/24 19:02, Andrew M.A. Cater wrote: > On Mon, Jul 08, 2024 at 06:08:49PM -0400, gene heskett wrote: >> On 7/8/24 17:20, Andy Smith wrote: >>> Hi, >>> >>> On Tue, Jul 09, 2024 at 12:15:00AM +0500, 타토카 wrote: >>>> I mean subscriptions like this "debian-user" >>> >>> The only cost associated with this mailing list is your sanity. >>> >> +1, Andy. Some of us get downright upset with the Karens that think they run >> this all volunteer show. I've unfortunately come to the conclusion they are >> best ignored. Generally, they don't seem to be members of a civil society, >> or to be able to learn how to treat their fellow man. Your monitoring, and >> howto corrections are much appreciated, thank you. >> >>> Thanks, >>> Andy >>> >> > > All contributions by any Andy gratefully received on this list. There > are also all sorts of people contributing to - and reading - this list. > Sometimes, even the worst of the passers by and trolls improve. > > Please don't stoop to characterising others too readily as you might > dissuade somebody from contributing who could be really valuable. All quite true Andy. But you may have noted that I only speak up from personal experience from having done it myself, not always in the approved way. > All the very best, as ever, > > Andy > (amacater@debian.org) Take care & stay well, Andy. >> Cheers, Gene Heskett, CET. >> -- >> "There are four boxes to be used in defense of liberty: >> soap, ballot, jury, and ammo. Please use in that order." >> -Ed Howdershelt (Author, 1940) >> If we desire respect for the law, we must first make the law respectable. >> - Louis D. Brandeis >> > > . Cheers, Gene Heskett, CET. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | 타토카 <cybertatoka@gmail.com> |
|---|---|
| Date | 2024-07-11 00:10 +0200 |
| Message-ID | <IYNFE-1dMg-21@gated-at.bofh.it> |
| In reply to | #270954 |
[Multipart message — attachments visible in raw view] — view raw
Hello, dear Debian Community. I just wanted to check a key with GPG. I have found this on https://www.debian.org/CD/verify: pub rsa4096/DA87E80D6294BE9B 2011-01-05 [SC] Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B uid Debian CD signing key <debian-cd@lists.debian.org> How can I download this key for GPG checking? Can I do next: gpg --keyserver keyring.debian.org --recv-keys DA87E80D6294BE9B If not, can you give an advice how to do it right?
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-11 01:10 +0200 |
| Message-ID | <IYOBH-1euu-1@gated-at.bofh.it> |
| In reply to | #271049 |
On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote: > > Hello, dear Debian Community. > > I just wanted to check a key with GPG. > > I have found this on https://www.debian.org/CD/verify: > > pub rsa4096/DA87E80D6294BE9B 2011-01-05 [SC] > > Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B > > uid Debian CD signing key <debian-cd@lists.debian.org> > > > How can I download this key for GPG checking? Click on the link, that takes you to https://www.debian.org/CD/key-DA87E80D6294BE9B.txt and save the file. Then gpg --import it $ gpg --import key-DA87E80D6294BE9B.txt gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys gpg: key DA87E80D6294BE9B: public key "Debian CD signing key <debian-cd@lists.debian.org>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: no ultimately trusted keys found hrmmm... 64 signatures not checked due to missing keys due to missing keys doesn't look good, but you've got the key now. I checked by going to http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got the SHA512SUMS and SHA512SUMS.sign files. Verify them by $ gpg --verify SHA512SUMS.sign SHA512SUMS gpg: Signature made Sat Jun 29 16:50:24 2024 EDT gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B so the contents of SHA512SUMS are trustworthy. Or as trustworthy as I can verify.. somebody else hopefully knows how to get all the missing keys and mark the DA87E80D6294BE9B key as trusted. and for whatever it's worth, I use these aliases: $ alias | grep sha alias sha1='/usr/bin/openssl dgst -sha1 ' alias sha256='/usr/bin/openssl dgst -sha256 ' alias sha512='/usr/bin/openssl dgst -sha512 ' Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | 타토카 <cybertatoka@gmail.com> |
|---|---|
| Date | 2024-07-11 13:50 +0200 |
| Message-ID | <IZ0tb-1mc8-1@gated-at.bofh.it> |
| In reply to | #271054 |
[Multipart message — attachments visible in raw view] — view raw
Why 64 signatures not checked and no ultimately trusted keys found here: $ gpg --import key-DA87E80D6294BE9B.txt gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys gpg: key DA87E80D6294BE9B: public key "Debian CD signing key <debian-cd@lists.debian.org>" imported gpg: Total number processed: 1 gpg: imported: 1 gpg: no ultimately trusted keys found And this: gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. This is weird. Why Fedora does not have this, but Debian does. And can you explain to me what is it, please? On Thu, Jul 11, 2024 at 4:00 AM Lee <ler762@gmail.com> wrote: > On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote: > > > > Hello, dear Debian Community. > > > > I just wanted to check a key with GPG. > > > > I have found this on https://www.debian.org/CD/verify: > > > > pub rsa4096/DA87E80D6294BE9B 2011-01-05 [SC] > > > > Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B > > > > uid Debian CD signing key <debian-cd@lists.debian.org> > > > > > > How can I download this key for GPG checking? > > Click on the link, that takes you to > https://www.debian.org/CD/key-DA87E80D6294BE9B.txt > and save the file. Then gpg --import it > > $ gpg --import key-DA87E80D6294BE9B.txt > gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys > gpg: key DA87E80D6294BE9B: public key "Debian CD signing key > <debian-cd@lists.debian.org>" imported > gpg: Total number processed: 1 > gpg: imported: 1 > gpg: no ultimately trusted keys found > > hrmmm... 64 signatures not checked due to missing keys due to missing > keys doesn't look good, but you've got the key now. > > I checked by going to > http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got > the SHA512SUMS and SHA512SUMS.sign files. > Verify them by > > $ gpg --verify SHA512SUMS.sign SHA512SUMS > gpg: Signature made Sat Jun 29 16:50:24 2024 EDT > gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B > gpg: Good signature from "Debian CD signing key > <debian-cd@lists.debian.org>" [unknown] > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. > Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B > > so the contents of SHA512SUMS are trustworthy. Or as trustworthy as I > can verify.. somebody else hopefully knows how to get all the missing > keys and mark the DA87E80D6294BE9B key as trusted. > > and for whatever it's worth, I use these aliases: > $ alias | grep sha > alias sha1='/usr/bin/openssl dgst -sha1 ' > alias sha256='/usr/bin/openssl dgst -sha256 ' > alias sha512='/usr/bin/openssl dgst -sha512 ' > > Regards, > Lee >
[toc] | [prev] | [next] | [standalone]
| From | 타토카 <cybertatoka@gmail.com> |
|---|---|
| Date | 2024-07-11 14:00 +0200 |
| Message-ID | <IZ0CR-1mgp-3@gated-at.bofh.it> |
| In reply to | #271072 |
[Multipart message — attachments visible in raw view] — view raw
And can you explain to me what is it, please? * $ alias | grep sha alias sha1='/usr/bin/openssl dgst -sha1 ' alias sha256='/usr/bin/openssl dgst -sha256 ' alias sha512='/usr/bin/openssl dgst -sha512 ' On Thu, Jul 11, 2024 at 4:47 PM 타토카 <cybertatoka@gmail.com> wrote: > Why 64 signatures not checked and no ultimately trusted keys found here: > $ gpg --import key-DA87E80D6294BE9B.txt > gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys > gpg: key DA87E80D6294BE9B: public key "Debian CD signing key > <debian-cd@lists.debian.org>" imported > gpg: Total number processed: 1 > gpg: imported: 1 > gpg: no ultimately trusted keys found > > And this: > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. > > This is weird. Why Fedora does not have this, but Debian does. > > And can you explain to me what is it, please? > > On Thu, Jul 11, 2024 at 4:00 AM Lee <ler762@gmail.com> wrote: > >> On Wed, Jul 10, 2024 at 6:07 PM 타토카 <cybertatoka@gmail.com> wrote: >> > >> > Hello, dear Debian Community. >> > >> > I just wanted to check a key with GPG. >> > >> > I have found this on https://www.debian.org/CD/verify: >> > >> > pub rsa4096/DA87E80D6294BE9B 2011-01-05 [SC] >> > >> > Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B >> > >> > uid Debian CD signing key <debian-cd@lists.debian.org> >> > >> > >> > How can I download this key for GPG checking? >> >> Click on the link, that takes you to >> https://www.debian.org/CD/key-DA87E80D6294BE9B.txt >> and save the file. Then gpg --import it >> >> $ gpg --import key-DA87E80D6294BE9B.txt >> gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys >> gpg: key DA87E80D6294BE9B: public key "Debian CD signing key >> <debian-cd@lists.debian.org>" imported >> gpg: Total number processed: 1 >> gpg: imported: 1 >> gpg: no ultimately trusted keys found >> >> hrmmm... 64 signatures not checked due to missing keys due to missing >> keys doesn't look good, but you've got the key now. >> >> I checked by going to >> http://mirror.us.leaseweb.net/debian-cd/12.6.0/amd64/iso-dvd/ and got >> the SHA512SUMS and SHA512SUMS.sign files. >> Verify them by >> >> $ gpg --verify SHA512SUMS.sign SHA512SUMS >> gpg: Signature made Sat Jun 29 16:50:24 2024 EDT >> gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B >> gpg: Good signature from "Debian CD signing key >> <debian-cd@lists.debian.org>" [unknown] >> gpg: WARNING: This key is not certified with a trusted signature! >> gpg: There is no indication that the signature belongs to the >> owner. >> Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 >> BE9B >> >> so the contents of SHA512SUMS are trustworthy. Or as trustworthy as I >> can verify.. somebody else hopefully knows how to get all the missing >> keys and mark the DA87E80D6294BE9B key as trusted. >> >> and for whatever it's worth, I use these aliases: >> $ alias | grep sha >> alias sha1='/usr/bin/openssl dgst -sha1 ' >> alias sha256='/usr/bin/openssl dgst -sha256 ' >> alias sha512='/usr/bin/openssl dgst -sha512 ' >> >> Regards, >> Lee >> >
[toc] | [prev] | [next] | [standalone]
| From | Franco Martelli <martellif67@gmail.com> |
|---|---|
| Date | 2024-07-11 21:30 +0200 |
| Message-ID | <IZ7Eo-1qDQ-9@gated-at.bofh.it> |
| In reply to | #271073 |
On 11/07/24 at 13:55, 타토카 wrote: > And can you explain to me what is it, please? * > > $ alias | grep sha > alias sha1='/usr/bin/openssl dgst -sha1 ' > alias sha256='/usr/bin/openssl dgst -sha256 ' > alias sha512='/usr/bin/openssl dgst -sha512 ' Since you are asking this question maybe you don't know that after verified the authenticity of SHA512SUMS.sign SHA512SUMS files you must use the file SHA512SUMS to verify the authenticity of the .iso files you will download. If you open SHA512SUMS in an editor you see a list of checksum that they belong to respective .iso or .torrent files. Recently I downloaded the "debian-12.6.0-amd64-DVD-1.iso" iso image using a .torrent file. After downloaded the .torrent file place it together SHA512SUMS in the same directory, then verify the authenticity with the command: $ sha512sum --ignore-missing -c SHA512SUMS debian-12.6.0-amd64-DVD-1.iso.torrent: OK Now you are ready to download the .iso, open the .torrent file in your favorite Torrent client and start the download, then check the authenticity of the .iso with exactly the same command: $ sha512sum --ignore-missing -c SHA512SUMS debian-12.6.0-amd64-DVD-1.iso: OK This step might take a while, so be patient, after done that you are ready to burn a DVD, copy the .iso to an USB key, install to a virtual machine… but this is another story ^_^ Cheers, -- Franco Martelli
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-11 22:00 +0200 |
| Message-ID | <IZ87n-1qNb-1@gated-at.bofh.it> |
| In reply to | #271073 |
On Thu, Jul 11, 2024 at 7:55 AM 타토카 <cybertatoka@gmail.com> wrote: > > And can you explain to me what is it, please? * > > $ alias | grep sha > alias sha1='/usr/bin/openssl dgst -sha1 ' > alias sha256='/usr/bin/openssl dgst -sha256 ' > alias sha512='/usr/bin/openssl dgst -sha512 ' It's a way of getting sha sums for a file. I've been carrying those in my .bashrc file for ages.. I don't remember if I didn't know about the sha1sum program or it didn't exist in cygwin at the time, but I found a method that worked and quit looking. By now it's "muscle memory" -- like returning from vacation and not being able to remember your password, but go down to the cafeteria, get a cup of coffee, return to your desk, turn your PC on and enter your password without thinking. I found a method that worked and don't think about it any more. You probably should use the sha1sum, sha256sum, sha512sum programs though - if only to reduce confusion when you're talking to other people :) Regards Lee
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2024-07-11 14:00 +0200 |
| Message-ID | <IZ0CR-1mgp-9@gated-at.bofh.it> |
| In reply to | #271072 |
On Thu, Jul 11, 2024 at 16:47:45 +0500, 타토카 wrote: > Why 64 signatures not checked and no ultimately trusted keys found here: > $ gpg --import key-DA87E80D6294BE9B.txt > gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys > gpg: key DA87E80D6294BE9B: public key "Debian CD signing key > <debian-cd@lists.debian.org>" imported > gpg: Total number processed: 1 > gpg: imported: 1 > gpg: no ultimately trusted keys found > > And this: > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. Because you haven't established a chain of trust from yourself to any of the signatures. You've downloaded this key from the Internet. And it's signed by 64 other keys. That's all you know. You have no idea whether any of those 64 signing keys are trustworthy. At some point, you have to say "This is good enough." And then you move on with your life, either installing Debian from the image that you have, or not. You've already done far more verification than most people do.
[toc] | [prev] | [next] | [standalone]
| From | 타토카 <cybertatoka@gmail.com> |
|---|---|
| Date | 2024-07-11 14:30 +0200 |
| Message-ID | <IZ15T-1mFL-1@gated-at.bofh.it> |
| In reply to | #271074 |
[Multipart message — attachments visible in raw view] — view raw
Ok, I think this is really enough for verification ( Maybe (^_^) ). But, what do you mean: "Because you haven't established a chain of trust from yourself to any of the signatures." Is it only for Debian developers? And is it very important? On Thu, Jul 11, 2024 at 4:58 PM Greg Wooledge <greg@wooledge.org> wrote: > On Thu, Jul 11, 2024 at 16:47:45 +0500, 타토카 wrote: > > Why 64 signatures not checked and no ultimately trusted keys found here: > > $ gpg --import key-DA87E80D6294BE9B.txt > > gpg: key DA87E80D6294BE9B: 64 signatures not checked due to missing keys > > gpg: key DA87E80D6294BE9B: public key "Debian CD signing key > > <debian-cd@lists.debian.org>" imported > > gpg: Total number processed: 1 > > gpg: imported: 1 > > gpg: no ultimately trusted keys found > > > > And this: > > gpg: WARNING: This key is not certified with a trusted signature! > > gpg: There is no indication that the signature belongs to the > > owner. > > Because you haven't established a chain of trust from yourself to any > of the signatures. > > You've downloaded this key from the Internet. And it's signed by 64 > other keys. That's all you know. You have no idea whether any of those > 64 signing keys are trustworthy. > > At some point, you have to say "This is good enough." And then you move > on with your life, either installing Debian from the image that you have, > or not. > > You've already done far more verification than most people do. > >
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2024-07-11 14:40 +0200 |
| Message-ID | <IZ1fz-1mIV-9@gated-at.bofh.it> |
| In reply to | #271075 |
Hi, cybertatoka@gmail.com wrote: > gpg: WARNING: This key is not certified with a trusted signature! That's normal. The concept of a "web of trust" suffers from the fact that most people which i know good enough to trust them in general have no idea of PGP and thus are not really trustworthy in special. https://en.wikipedia.org/wiki/Web_of_trust The best verification you can get outside the web of trust is the key fingerprint which must match one of the published fingerprints on https://www.debian.org/CD/verify I deem them trustworthy because they did not change in years. (Cryptographers might object that old keys are poor keys. But they will also be right with telling you that cryptography is a minefield and thus amateurs like us should stay away from it.) > And can you explain to me what is it, please? > $ alias | grep sha > alias sha1='/usr/bin/openssl dgst -sha1 ' > alias sha256='/usr/bin/openssl dgst -sha256 ' > alias sha512='/usr/bin/openssl dgst -sha512 ' Shell commands "sha1", "sha256", and "sha512" were somewhere defined to actually be runs of program /usr/bin/openssl with the checksum algorithms given by the command names. Usually people get told to use shell commands "sha256sum" and "sha512sum" which are supposed to run the programs /usr/bin/sha256sum and /usr/bin/sha512sum from package "coreutils". In order to find out from where the "alias" definitions stem, you will have to check the startup scripts of your shell. Like ~/.bashrc . Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2024-07-11 14:40 +0200 |
| Message-ID | <IZ1fz-1mIV-11@gated-at.bofh.it> |
| In reply to | #271075 |
On Thu, Jul 11, 2024 at 17:23:43 +0500, 타토카 wrote: > But, what do you mean: "Because you haven't established a chain of trust > from yourself to any of the signatures." Imagine someone walks up to you on the street and hands you a contract, which is signed by someone you've never heard of. You don't know the guy who gave you the contract. You've never seen him before. So, you don't trust him. You can do a little bit of research on the person whose signature is on the contract. Maybe she's famous. You look her up on the Internet, and it turns out that she's well known in certain circles. If her signature is on this contract, then the contract is probably worth something. But how do you know whether this is really her signature, or a forgery? If you knew her in person, you could go to her office, ask her to sign something in your presence, and compare her signature to the one you see on the contract. But you don't know her in person. She lives really far away, and she's too important and too busy to want to spend a lot of time signing blank pieces of paper for people like you anyway. But maybe you know someone who knows her. Your lawyer friend -- maybe he's worked with her before. He might know what her signature looks like. He might be able to tell you whether the signature on the contract is valid. So, you go to your lawyer friend, and you show him the contract, and he says "Yeah, that looks legit." Now you know what her signature looks like, or at least you've got verification from a source that you trust. > Is it only for Debian developers? And is it very important? In theory, anybody can attend a key signing party, and get in-person verification of various GPG keys. Once you've got a few keys from people that you trust, your web of trust expands. If you've got a trusted key from Joe Smith, and Joe Smith says he trusts a key belonging to Sara Jones, and Sara Jones says she trusts the Debian signing key that you're trying to verify, then you have a chain of trust from yourself, to Joe, to Sara, to the Debian key. In practice, very few people do this, because it's a LOT of effort.
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2024-07-11 15:50 +0200 |
| Message-ID | <IZ2lj-1nlp-1@gated-at.bofh.it> |
| In reply to | #271077 |
[Multipart message — attachments visible in raw view] — view raw
On Jul 11, 2024, Greg Wooledge wrote:
> On Thu, Jul 11, 2024 at 17:23:43 +0500, 타토카 wrote:
> > But, what do you mean: "Because you haven't established a chain of trust
> > from yourself to any of the signatures."
>
> Imagine someone walks up to you on the street and hands you a contract,
> which is signed by someone you've never heard of.
>
> You don't know the guy who gave you the contract. You've never seen him
> before. So, you don't trust him. [...]
I always liked the analogy of schoolwork / notes.
Say you missed last Friday's class, and you need the notes (where "the
notes" correspond to "the pgp key in question").
Scenario A: "untrusted" ("website with a link / posted fingerprint")
You run into someone from class, who you don't really know all that
well, but you do know they answer the professor pretty often (and
correctly at that).
Scenario B: "web of trust" ("one or more trusted signatures on that key")
Nearly the same as "A", but the other person is a friend-of-a-friend.
You can ask your friend when you meet them for lunch if you can trust
the classmate's notes.
Scenario C: "fully trusted" ("you made the effort to verify the owner")
You ask you best friend since second grade for their notes. You know
they've been an "A" student since forever, and they take amazing notes.
--
|_|O|_|
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1 E067 6D65 70E5 4CE7 2860
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web