Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207054 > unrolled thread

Verifying authenticity of Debian CDs

Started byChris XX <1swansboro@gmail.com>
First post2019-04-05 22:50 +0200
Last post2019-04-06 12:30 +0200
Articles 8 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  Verifying authenticity of Debian CDs Chris XX <1swansboro@gmail.com> - 2019-04-05 22:50 +0200
    Re: Verifying authenticity of Debian CDs Lee <ler762@gmail.com> - 2019-04-06 00:00 +0200
    Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-06 00:10 +0200
      Re: Verifying authenticity of Debian CDs Default User <hunguponcontent@gmail.com> - 2019-04-11 18:40 +0200
        Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-11 22:30 +0200
      Re: Verifying authenticity of Debian CDs Steve McIntyre <steve@einval.com> - 2019-04-29 19:40 +0200
        Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-29 20:20 +0200
    Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-06 12:30 +0200

#207054 — Verifying authenticity of Debian CDs

FromChris XX <1swansboro@gmail.com>
Date2019-04-05 22:50 +0200
SubjectVerifying authenticity of Debian CDs
Message-ID<xJDWF-3fQ-9@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

I was trying to Verify the authenticity of Debian CDs on your website, but
I don't see instructions that will guide me through the process
(step-by-step).

Can you help and/or fix?
Thanks, Chris

P.S.  this was the site I got stuck on:
https://www.debian.org/CD/verify

There is a lot of information, but no clear guidence. For example, do I
install Debian first then look somewhere for the *"fingerprints"*

I don't understand the use of this tool: *"you should use the tools
sha256sum or sha512sum to work with these."*

[toc] | [next] | [standalone]


#207056

FromLee <ler762@gmail.com>
Date2019-04-06 00:00 +0200
Message-ID<xJF2r-3XX-7@gated-at.bofh.it>
In reply to#207054
On 4/5/19, Chris XX <1swansboro@gmail.com> wrote:
> I was trying to Verify the authenticity of Debian CDs on your website, but
> I don't see instructions that will guide me through the process
> (step-by-step).
>
> Can you help and/or fix?
> Thanks, Chris
>
> P.S.  this was the site I got stuck on:
> https://www.debian.org/CD/verify
>
> There is a lot of information, but no clear guidence. For example, do I
> install Debian first then look somewhere for the *"fingerprints"*
>
> I don't understand the use of this tool: *"you should use the tools
> sha256sum or sha512sum to work with these."*

I'm the wrong person to explain verifying signatures, so I'll skip all
that & go with

- download the iso file
- download the SHA256SUM file
- compute the checksum of the downloaded file & compare to what's in
the SHA256SUM file.  If they match you've verified the download.

So let's pretend you started from
  https://cdimage.debian.org/debian-cd/current/i386/iso-cd/

and downloaded
  debian-9.8.0-i386-netinst.iso
You also need to download the SHA256SUMS file

If you're on Windows, compute the checksum by doing
  certutil -hashfile debian-9.8.0-i386-netinst.iso SHA256
and compare that to
  8156cc4ce7a06facf69d4f7161f89431a794cdaba8e2b4eb91b2c43a302e4614
(the checksum listed in the SHA256SUMS file)

If you're already on Debian you've got the sha256sum program, so do
  sha256sum debian-9.8.0-i386-netinst.iso
and compare the output to the checksum in SHA256SUMS file

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#207057

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2019-04-06 00:10 +0200
Message-ID<xJFc5-4gL-5@gated-at.bofh.it>
In reply to#207054
Hi,

Chris XX wrote:
> I was trying to Verify the authenticity of Debian CDs on your website, but I
> don't see instructions that will guide me through the process
> (step-by-step).

(We are the users. But some Debian Developers are watching, too.)

Obviously there is a gap between checksum file verification and .iso image
verification.

Let's first look at the files offered for download:
  https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
has among others

  SHA512SUMS.sign
  SHA512SUMS
  debian-9.8.0-amd64-netinst.iso

> https://www.debian.org/CD/verify

This publishes the key "fingerprints" by which you can recognize authentic
pairs of SHA512SUMS.sign and SHA512SUMS.

It points to
  https://keyring.debian.org/
where you probably shall learn how to obtain the keys in question,
namely by the shell commands

  gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
  gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
  gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3

Experienced users of gpg would know that one can check authenticity by

  gpg --verify SHA512SUMS.sign SHA512SUMS

which should say something like

  gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID 6294BE9B
  gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>"
  gpg: WARNING: This key is not certified with a trusted signature!
  gpg:          There is no indication that the signature belongs to the owner.
  Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

The reported fingerprint must be one of the published fingerprints,
or else something is fishy.
Here it is the Debian one of 2011-01-05. I.e. all is well so far.

If you change some character in SHA512SUMS and run above command again
then you will see

  gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID 6294BE9B
  gpg: BAD signature from "Debian CD signing key <debian-cd@lists.debian.org>"


So you can trust the content of SHA512SUMS, if gpg --verify says it is
good and if the key fingerprint matches one of the Debian fingerprints.

Now you have to follow the tiny link "faq" at the bottom to
  https://www.debian.org/CD/faq/
where you hop to
  https://www.debian.org/CD/faq/#verify

Between the lines you read that there is a text line in SHA512SUMS which
shows the name of the .iso file which you actually want to verify:

  cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245  debian-9.8.0-amd64-netinst.iso

More explicite is the hint to use program "sha512sum". A run of

  sha512sum debian-9.8.0-amd64-netinst.iso

puts out

  cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245  debian-9.8.0-amd64-netinst.iso

which you should compare with the line in SHA512SUMS.

Alternatively you could run

  sha512sum --check SHA512SUMS 2>/dev/null

to get

  debian-9.8.0-amd64-netinst.iso: OK
  debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read
  debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read

Or you could download

  https://people.debian.org/~danchev/debian-iso/check_debian_iso

and run

  chmod u+x ./check_debian_iso
  ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso

to get

  Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through 'sha512sum'
  to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'.
  149504+0 records in
  149504+0 records out
  306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s
  Ok: 'debian-9.8.0-amd64-netinst.iso' matches 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'


Now let's see what happens if a single byte is altered in the .iso

  dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511 of=debian-9.8.0-amd64-netinst.iso

Now the proposed verifyier runs yield:

  0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229  debian-9.8.0-amd64-netinst.iso

which does obviously not match the line in SHA512SUMS, or

  debian-9.8.0-amd64-netinst.iso: FAILED
  ...

or

  ...
  Found:     0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
  Expected:  cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
  MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'

So you know that the checksumers really detect nearly all damages of
debian-9.8.0-amd64-netinst.iso.

--------------------------------------------------------------------------

@ Steve McIntyre (maintainer of debian-cd):

Do you agree with the instructions above ?

Is there a consolidated wiki page with such instructions which i failed
to find ? If not: shall we make such a page ?


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#207329

FromDefault User <hunguponcontent@gmail.com>
Date2019-04-11 18:40 +0200
Message-ID<xLKU2-Rg-11@gated-at.bofh.it>
In reply to#207057

[Multipart message — attachments visible in raw view] — view raw

On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote:

> Hi,
>
> Chris XX wrote:
> > I was trying to Verify the authenticity of Debian CDs on your website,
> but I
> > don't see instructions that will guide me through the process
> > (step-by-step).
>
> (We are the users. But some Debian Developers are watching, too.)
>
> Obviously there is a gap between checksum file verification and .iso image
> verification.
>
> Let's first look at the files offered for download:
>   https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
> has among others
>
>   SHA512SUMS.sign
>   SHA512SUMS
>   debian-9.8.0-amd64-netinst.iso
>
> > https://www.debian.org/CD/verify
>
> This publishes the key "fingerprints" by which you can recognize authentic
> pairs of SHA512SUMS.sign and SHA512SUMS.
>
> It points to
>   https://keyring.debian.org/
> where you probably shall learn how to obtain the keys in question,
> namely by the shell commands
>
>   gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
>   gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
>   gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3
>
> Experienced users of gpg would know that one can check authenticity by
>
>   gpg --verify SHA512SUMS.sign SHA512SUMS
>
> which should say something like
>
>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
> 6294BE9B
>   gpg: Good signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>   gpg: WARNING: This key is not certified with a trusted signature!
>   gpg:          There is no indication that the signature belongs to the
> owner.
>   Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
> BE9B
>
> The reported fingerprint must be one of the published fingerprints,
> or else something is fishy.
> Here it is the Debian one of 2011-01-05. I.e. all is well so far.
>
> If you change some character in SHA512SUMS and run above command again
> then you will see
>
>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
> 6294BE9B
>   gpg: BAD signature from "Debian CD signing key <
> debian-cd@lists.debian.org>"
>
>
> So you can trust the content of SHA512SUMS, if gpg --verify says it is
> good and if the key fingerprint matches one of the Debian fingerprints.
>
> Now you have to follow the tiny link "faq" at the bottom to
>   https://www.debian.org/CD/faq/
> where you hop to
>   https://www.debian.org/CD/faq/#verify
>
> Between the lines you read that there is a text line in SHA512SUMS which
> shows the name of the .iso file which you actually want to verify:
>
>
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
> debian-9.8.0-amd64-netinst.iso
>
> More explicite is the hint to use program "sha512sum". A run of
>
>   sha512sum debian-9.8.0-amd64-netinst.iso
>
> puts out
>
>
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
> debian-9.8.0-amd64-netinst.iso
>
> which you should compare with the line in SHA512SUMS.
>
> Alternatively you could run
>
>   sha512sum --check SHA512SUMS 2>/dev/null
>
> to get
>
>   debian-9.8.0-amd64-netinst.iso: OK
>   debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read
>   debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read
>
> Or you could download
>
>   https://people.debian.org/~danchev/debian-iso/check_debian_iso
>
> and run
>
>   chmod u+x ./check_debian_iso
>   ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso
>
> to get
>
>   Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through
> 'sha512sum'
>   to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'.
>   149504+0 records in
>   149504+0 records out
>   306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s
>   Ok: 'debian-9.8.0-amd64-netinst.iso' matches
> 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'
>
>
> Now let's see what happens if a single byte is altered in the .iso
>
>   dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511
> of=debian-9.8.0-amd64-netinst.iso
>
> Now the proposed verifyier runs yield:
>
>
> 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
> debian-9.8.0-amd64-netinst.iso
>
> which does obviously not match the line in SHA512SUMS, or
>
>   debian-9.8.0-amd64-netinst.iso: FAILED
>   ...
>
> or
>
>   ...
>   Found:
>  0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
>   Expected:
> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>   MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from
> 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'
>
> So you know that the checksumers really detect nearly all damages of
> debian-9.8.0-amd64-netinst.iso.
>
> --------------------------------------------------------------------------
>
> @ Steve McIntyre (maintainer of debian-cd):
>
> Do you agree with the instructions above ?
>
> Is there a consolidated wiki page with such instructions which i failed
> to find ? If not: shall we make such a page ?
>
>
> Have a nice day :)
>
> Thomas
>


Thomas, thank you for posting this.

It is a good "walk-through" of the verification process. Unfortunately,
proper verification can seem too complicated for some users, especially
newer ones.  So often they just:

sha512 sum debian-9.8.0-amd64-netinst.iso

say, "looks about the same", and call it a day.

Hopefully this will help someone.

Thanks again.

[toc] | [prev] | [next] | [standalone]


#207341

Fromjohn doe <johndoe65534@mail.com>
Date2019-04-11 22:30 +0200
Message-ID<xLOuB-37X-1@gated-at.bofh.it>
In reply to#207329
On 4/11/2019 6:35 PM, Default User wrote:
> On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote:
>
>> Hi,
>>
>> Chris XX wrote:
>>> I was trying to Verify the authenticity of Debian CDs on your website,
>> but I
>>> don't see instructions that will guide me through the process
>>> (step-by-step).
>>
>> (We are the users. But some Debian Developers are watching, too.)
>>
>> Obviously there is a gap between checksum file verification and .iso image
>> verification.
>>
>> Let's first look at the files offered for download:
>>   https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
>> has among others
>>
>>   SHA512SUMS.sign
>>   SHA512SUMS
>>   debian-9.8.0-amd64-netinst.iso
>>
>>> https://www.debian.org/CD/verify
>>
>> This publishes the key "fingerprints" by which you can recognize authentic
>> pairs of SHA512SUMS.sign and SHA512SUMS.
>>
>> It points to
>>   https://keyring.debian.org/
>> where you probably shall learn how to obtain the keys in question,
>> namely by the shell commands
>>
>>   gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
>>   gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
>>   gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3
>>
>> Experienced users of gpg would know that one can check authenticity by
>>
>>   gpg --verify SHA512SUMS.sign SHA512SUMS
>>
>> which should say something like
>>
>>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
>> 6294BE9B
>>   gpg: Good signature from "Debian CD signing key <
>> debian-cd@lists.debian.org>"
>>   gpg: WARNING: This key is not certified with a trusted signature!
>>   gpg:          There is no indication that the signature belongs to the
>> owner.
>>   Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
>> BE9B
>>
>> The reported fingerprint must be one of the published fingerprints,
>> or else something is fishy.
>> Here it is the Debian one of 2011-01-05. I.e. all is well so far.
>>
>> If you change some character in SHA512SUMS and run above command again
>> then you will see
>>
>>   gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
>> 6294BE9B
>>   gpg: BAD signature from "Debian CD signing key <
>> debian-cd@lists.debian.org>"
>>
>>
>> So you can trust the content of SHA512SUMS, if gpg --verify says it is
>> good and if the key fingerprint matches one of the Debian fingerprints.
>>
>> Now you have to follow the tiny link "faq" at the bottom to
>>   https://www.debian.org/CD/faq/
>> where you hop to
>>   https://www.debian.org/CD/faq/#verify
>>
>> Between the lines you read that there is a text line in SHA512SUMS which
>> shows the name of the .iso file which you actually want to verify:
>>
>>
>> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>> debian-9.8.0-amd64-netinst.iso
>>
>> More explicite is the hint to use program "sha512sum". A run of
>>
>>   sha512sum debian-9.8.0-amd64-netinst.iso
>>
>> puts out
>>
>>
>> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>> debian-9.8.0-amd64-netinst.iso
>>
>> which you should compare with the line in SHA512SUMS.
>>
>> Alternatively you could run
>>
>>   sha512sum --check SHA512SUMS 2>/dev/null
>>
The STDERR redirection to the null device could be avoided by using
'--ignore-missing'.

$ sha512sum -c --ignore-missing <CHECKSUM-FILE>

The '--strict' option could also be used.


"The following five options are useful only when verifying checksums:
...
      --ignore-missing  don't fail or report status for missing files
...
      --strict         exit non-zero for improperly formatted checksum lines
..."

--
John Doe

[toc] | [prev] | [next] | [standalone]


#207982

FromSteve McIntyre <steve@einval.com>
Date2019-04-29 19:40 +0200
Message-ID<xSipY-4Tj-5@gated-at.bofh.it>
In reply to#207057
[ I often skim the debian-user list, but when I'm away on vacation or
  at a conference I'll miss things unless I'm directly CC:ed ]

Thomas wrote:
>Hi,
>
>Chris XX wrote:
>> I was trying to Verify the authenticity of Debian CDs on your website, but I
>> don't see instructions that will guide me through the process
>> (step-by-step).
>
>(We are the users. But some Debian Developers are watching, too.)
>
>Obviously there is a gap between checksum file verification and .iso image
>verification.
>
>Let's first look at the files offered for download:
>  https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
>has among others

...

>  ...
>  Found:    
>0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229
>  Expected: 
>cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>  MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS'
>
>So you know that the checksumers really detect nearly all damages of
>debian-9.8.0-amd64-netinst.iso.
>
>--------------------------------------------------------------------------
>
>@ Steve McIntyre (maintainer of debian-cd):
>
>Do you agree with the instructions above ?

Yes, that's a very clear description. Thanks!

>Is there a consolidated wiki page with such instructions which i failed
>to find ? If not: shall we make such a page ?

I'm working with the web team to update our web pages for image
download, and part of that will include a much clearer set of
verification instructions. If you're happy for me to borrow your text
above, I think it's a good start!

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
  Armed with "Valor": "Centurion" represents quality of Discipline,
  Honor, Integrity and Loyalty. Now you don't have to be a Caesar to
  concord the digital world while feeling safe and proud.

[toc] | [prev] | [next] | [standalone]


#207984

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2019-04-29 20:20 +0200
Message-ID<xSj2F-5nc-1@gated-at.bofh.it>
In reply to#207982
Hi,

i wrote in https://lists.debian.org/debian-user/2019/04/msg00214.html
> > > SHA512SUMS.sign [...] SHA512SUMS [...] debian-9.8.0-amd64-netinst.iso

john doe wrote:
> > $ sha512sum -c --ignore-missing <CHECKSUM-FILE>
> > The '--strict' option could also be used.

Steve McIntyre wrote:
> If you're happy for me to borrow your text
> above, I think it's a good start!

I meanwhile discovered that i already wrote a more concise wiki paragraph
about that issue:
  https://wiki.debian.org/JigdoOnLive#Verify_the_Debian_Live_download

Especially this line

  gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS

is obviously an improvement over mine in msg00214.html

  gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
  gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
  gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3
  gpg --verify SHA512SUMS.sign SHA512SUMS

(In that wiki i propose to first verify the SHA512SUMS and afterwards
 the gpg signature.
 IIRC, i had in mind that transport damage of the ISO is more likely
 than transport damage of the SHA512SUMS file or malicious activities.
 Whether this is a valid idea stays undecided ... scratching head.)


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#207070

Fromjohn doe <johndoe65534@mail.com>
Date2019-04-06 12:30 +0200
Message-ID<xJQKd-2WA-7@gated-at.bofh.it>
In reply to#207054
On 4/5/2019 10:26 PM, Chris XX wrote:
> I was trying to Verify the authenticity of Debian CDs on your website, but

What flavor of Debian do you want to instal?
What OS ("linux","Windows,""Mac") are you using to download "Debian"?

> I don't see instructions that will guide me through the process
> (step-by-step).
>

Answers to the above questions are required to be able to answer this
question.

This process is actualy in two folds:
- Insuring that the downloaded file is properly downloaded
- Verifying that the downloaded file has not been tampered with

To do that for  a Debian file three files are needed:
- SHA512SUMS.sign
- SHA512SUMS
- Iso file

--
John Doe

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web