Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #207054 > unrolled thread
| Started by | Chris XX <1swansboro@gmail.com> |
|---|---|
| First post | 2019-04-05 22:50 +0200 |
| Last post | 2019-04-06 12:30 +0200 |
| Articles | 8 — 6 participants |
Back to article view | Back to linux.debian.user
Verifying authenticity of Debian CDs Chris XX <1swansboro@gmail.com> - 2019-04-05 22:50 +0200
Re: Verifying authenticity of Debian CDs Lee <ler762@gmail.com> - 2019-04-06 00:00 +0200
Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-06 00:10 +0200
Re: Verifying authenticity of Debian CDs Default User <hunguponcontent@gmail.com> - 2019-04-11 18:40 +0200
Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-11 22:30 +0200
Re: Verifying authenticity of Debian CDs Steve McIntyre <steve@einval.com> - 2019-04-29 19:40 +0200
Re: Verifying authenticity of Debian CDs "Thomas Schmitt" <scdbackup@gmx.net> - 2019-04-29 20:20 +0200
Re: Verifying authenticity of Debian CDs john doe <johndoe65534@mail.com> - 2019-04-06 12:30 +0200
| From | Chris XX <1swansboro@gmail.com> |
|---|---|
| Date | 2019-04-05 22:50 +0200 |
| Subject | Verifying authenticity of Debian CDs |
| Message-ID | <xJDWF-3fQ-9@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
I was trying to Verify the authenticity of Debian CDs on your website, but I don't see instructions that will guide me through the process (step-by-step). Can you help and/or fix? Thanks, Chris P.S. this was the site I got stuck on: https://www.debian.org/CD/verify There is a lot of information, but no clear guidence. For example, do I install Debian first then look somewhere for the *"fingerprints"* I don't understand the use of this tool: *"you should use the tools sha256sum or sha512sum to work with these."*
[toc] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2019-04-06 00:00 +0200 |
| Message-ID | <xJF2r-3XX-7@gated-at.bofh.it> |
| In reply to | #207054 |
On 4/5/19, Chris XX <1swansboro@gmail.com> wrote: > I was trying to Verify the authenticity of Debian CDs on your website, but > I don't see instructions that will guide me through the process > (step-by-step). > > Can you help and/or fix? > Thanks, Chris > > P.S. this was the site I got stuck on: > https://www.debian.org/CD/verify > > There is a lot of information, but no clear guidence. For example, do I > install Debian first then look somewhere for the *"fingerprints"* > > I don't understand the use of this tool: *"you should use the tools > sha256sum or sha512sum to work with these."* I'm the wrong person to explain verifying signatures, so I'll skip all that & go with - download the iso file - download the SHA256SUM file - compute the checksum of the downloaded file & compare to what's in the SHA256SUM file. If they match you've verified the download. So let's pretend you started from https://cdimage.debian.org/debian-cd/current/i386/iso-cd/ and downloaded debian-9.8.0-i386-netinst.iso You also need to download the SHA256SUMS file If you're on Windows, compute the checksum by doing certutil -hashfile debian-9.8.0-i386-netinst.iso SHA256 and compare that to 8156cc4ce7a06facf69d4f7161f89431a794cdaba8e2b4eb91b2c43a302e4614 (the checksum listed in the SHA256SUMS file) If you're already on Debian you've got the sha256sum program, so do sha256sum debian-9.8.0-i386-netinst.iso and compare the output to the checksum in SHA256SUMS file Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2019-04-06 00:10 +0200 |
| Message-ID | <xJFc5-4gL-5@gated-at.bofh.it> |
| In reply to | #207054 |
Hi, Chris XX wrote: > I was trying to Verify the authenticity of Debian CDs on your website, but I > don't see instructions that will guide me through the process > (step-by-step). (We are the users. But some Debian Developers are watching, too.) Obviously there is a gap between checksum file verification and .iso image verification. Let's first look at the files offered for download: https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/ has among others SHA512SUMS.sign SHA512SUMS debian-9.8.0-amd64-netinst.iso > https://www.debian.org/CD/verify This publishes the key "fingerprints" by which you can recognize authentic pairs of SHA512SUMS.sign and SHA512SUMS. It points to https://keyring.debian.org/ where you probably shall learn how to obtain the keys in question, namely by the shell commands gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D gpg --keyserver keyring.debian.org --recv-keys 6294BE9B gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3 Experienced users of gpg would know that one can check authenticity by gpg --verify SHA512SUMS.sign SHA512SUMS which should say something like gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID 6294BE9B gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B The reported fingerprint must be one of the published fingerprints, or else something is fishy. Here it is the Debian one of 2011-01-05. I.e. all is well so far. If you change some character in SHA512SUMS and run above command again then you will see gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID 6294BE9B gpg: BAD signature from "Debian CD signing key <debian-cd@lists.debian.org>" So you can trust the content of SHA512SUMS, if gpg --verify says it is good and if the key fingerprint matches one of the Debian fingerprints. Now you have to follow the tiny link "faq" at the bottom to https://www.debian.org/CD/faq/ where you hop to https://www.debian.org/CD/faq/#verify Between the lines you read that there is a text line in SHA512SUMS which shows the name of the .iso file which you actually want to verify: cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 debian-9.8.0-amd64-netinst.iso More explicite is the hint to use program "sha512sum". A run of sha512sum debian-9.8.0-amd64-netinst.iso puts out cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 debian-9.8.0-amd64-netinst.iso which you should compare with the line in SHA512SUMS. Alternatively you could run sha512sum --check SHA512SUMS 2>/dev/null to get debian-9.8.0-amd64-netinst.iso: OK debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read Or you could download https://people.debian.org/~danchev/debian-iso/check_debian_iso and run chmod u+x ./check_debian_iso ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso to get Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through 'sha512sum' to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'. 149504+0 records in 149504+0 records out 306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s Ok: 'debian-9.8.0-amd64-netinst.iso' matches 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' Now let's see what happens if a single byte is altered in the .iso dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511 of=debian-9.8.0-amd64-netinst.iso Now the proposed verifyier runs yield: 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 debian-9.8.0-amd64-netinst.iso which does obviously not match the line in SHA512SUMS, or debian-9.8.0-amd64-netinst.iso: FAILED ... or ... Found: 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 Expected: cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' So you know that the checksumers really detect nearly all damages of debian-9.8.0-amd64-netinst.iso. -------------------------------------------------------------------------- @ Steve McIntyre (maintainer of debian-cd): Do you agree with the instructions above ? Is there a consolidated wiki page with such instructions which i failed to find ? If not: shall we make such a page ? Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | Default User <hunguponcontent@gmail.com> |
|---|---|
| Date | 2019-04-11 18:40 +0200 |
| Message-ID | <xLKU2-Rg-11@gated-at.bofh.it> |
| In reply to | #207057 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote: > Hi, > > Chris XX wrote: > > I was trying to Verify the authenticity of Debian CDs on your website, > but I > > don't see instructions that will guide me through the process > > (step-by-step). > > (We are the users. But some Debian Developers are watching, too.) > > Obviously there is a gap between checksum file verification and .iso image > verification. > > Let's first look at the files offered for download: > https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/ > has among others > > SHA512SUMS.sign > SHA512SUMS > debian-9.8.0-amd64-netinst.iso > > > https://www.debian.org/CD/verify > > This publishes the key "fingerprints" by which you can recognize authentic > pairs of SHA512SUMS.sign and SHA512SUMS. > > It points to > https://keyring.debian.org/ > where you probably shall learn how to obtain the keys in question, > namely by the shell commands > > gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D > gpg --keyserver keyring.debian.org --recv-keys 6294BE9B > gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3 > > Experienced users of gpg would know that one can check authenticity by > > gpg --verify SHA512SUMS.sign SHA512SUMS > > which should say something like > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: Good signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the > owner. > Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 > BE9B > > The reported fingerprint must be one of the published fingerprints, > or else something is fishy. > Here it is the Debian one of 2011-01-05. I.e. all is well so far. > > If you change some character in SHA512SUMS and run above command again > then you will see > > gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID > 6294BE9B > gpg: BAD signature from "Debian CD signing key < > debian-cd@lists.debian.org>" > > > So you can trust the content of SHA512SUMS, if gpg --verify says it is > good and if the key fingerprint matches one of the Debian fingerprints. > > Now you have to follow the tiny link "faq" at the bottom to > https://www.debian.org/CD/faq/ > where you hop to > https://www.debian.org/CD/faq/#verify > > Between the lines you read that there is a text line in SHA512SUMS which > shows the name of the .iso file which you actually want to verify: > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > More explicite is the hint to use program "sha512sum". A run of > > sha512sum debian-9.8.0-amd64-netinst.iso > > puts out > > > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > debian-9.8.0-amd64-netinst.iso > > which you should compare with the line in SHA512SUMS. > > Alternatively you could run > > sha512sum --check SHA512SUMS 2>/dev/null > > to get > > debian-9.8.0-amd64-netinst.iso: OK > debian-9.8.0-amd64-xfce-CD-1.iso: FAILED open or read > debian-mac-9.8.0-amd64-netinst.iso: FAILED open or read > > Or you could download > > https://people.debian.org/~danchev/debian-iso/check_debian_iso > > and run > > chmod u+x ./check_debian_iso > ./check_debian_iso SHA512SUMS debian-9.8.0-amd64-netinst.iso > > to get > > Piping 149504 blocks of 'debian-9.8.0-amd64-netinst.iso' through > 'sha512sum' > to verify checksum list item 'debian-9.8.0-amd64-netinst.iso'. > 149504+0 records in > 149504+0 records out > 306184192 bytes (306 MB) copied, 0.882765 s, 347 MB/s > Ok: 'debian-9.8.0-amd64-netinst.iso' matches > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > > Now let's see what happens if a single byte is altered in the .iso > > dd if=/dev/zero bs=1 count=1 conv=notrunc seek=511 > of=debian-9.8.0-amd64-netinst.iso > > Now the proposed verifyier runs yield: > > > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > debian-9.8.0-amd64-netinst.iso > > which does obviously not match the line in SHA512SUMS, or > > debian-9.8.0-amd64-netinst.iso: FAILED > ... > > or > > ... > Found: > 0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > Expected: > cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from > 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > > So you know that the checksumers really detect nearly all damages of > debian-9.8.0-amd64-netinst.iso. > > -------------------------------------------------------------------------- > > @ Steve McIntyre (maintainer of debian-cd): > > Do you agree with the instructions above ? > > Is there a consolidated wiki page with such instructions which i failed > to find ? If not: shall we make such a page ? > > > Have a nice day :) > > Thomas > Thomas, thank you for posting this. It is a good "walk-through" of the verification process. Unfortunately, proper verification can seem too complicated for some users, especially newer ones. So often they just: sha512 sum debian-9.8.0-amd64-netinst.iso say, "looks about the same", and call it a day. Hopefully this will help someone. Thanks again.
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-04-11 22:30 +0200 |
| Message-ID | <xLOuB-37X-1@gated-at.bofh.it> |
| In reply to | #207329 |
On 4/11/2019 6:35 PM, Default User wrote:
> On Fri, Apr 5, 2019, 18:06 Thomas Schmitt <scdbackup@gmx.net> wrote:
>
>> Hi,
>>
>> Chris XX wrote:
>>> I was trying to Verify the authenticity of Debian CDs on your website,
>> but I
>>> don't see instructions that will guide me through the process
>>> (step-by-step).
>>
>> (We are the users. But some Debian Developers are watching, too.)
>>
>> Obviously there is a gap between checksum file verification and .iso image
>> verification.
>>
>> Let's first look at the files offered for download:
>> https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/
>> has among others
>>
>> SHA512SUMS.sign
>> SHA512SUMS
>> debian-9.8.0-amd64-netinst.iso
>>
>>> https://www.debian.org/CD/verify
>>
>> This publishes the key "fingerprints" by which you can recognize authentic
>> pairs of SHA512SUMS.sign and SHA512SUMS.
>>
>> It points to
>> https://keyring.debian.org/
>> where you probably shall learn how to obtain the keys in question,
>> namely by the shell commands
>>
>> gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D
>> gpg --keyserver keyring.debian.org --recv-keys 6294BE9B
>> gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3
>>
>> Experienced users of gpg would know that one can check authenticity by
>>
>> gpg --verify SHA512SUMS.sign SHA512SUMS
>>
>> which should say something like
>>
>> gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
>> 6294BE9B
>> gpg: Good signature from "Debian CD signing key <
>> debian-cd@lists.debian.org>"
>> gpg: WARNING: This key is not certified with a trusted signature!
>> gpg: There is no indication that the signature belongs to the
>> owner.
>> Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294
>> BE9B
>>
>> The reported fingerprint must be one of the published fingerprints,
>> or else something is fishy.
>> Here it is the Debian one of 2011-01-05. I.e. all is well so far.
>>
>> If you change some character in SHA512SUMS and run above command again
>> then you will see
>>
>> gpg: Signature made Sun 17 Feb 2019 04:10:30 PM CET using RSA key ID
>> 6294BE9B
>> gpg: BAD signature from "Debian CD signing key <
>> debian-cd@lists.debian.org>"
>>
>>
>> So you can trust the content of SHA512SUMS, if gpg --verify says it is
>> good and if the key fingerprint matches one of the Debian fingerprints.
>>
>> Now you have to follow the tiny link "faq" at the bottom to
>> https://www.debian.org/CD/faq/
>> where you hop to
>> https://www.debian.org/CD/faq/#verify
>>
>> Between the lines you read that there is a text line in SHA512SUMS which
>> shows the name of the .iso file which you actually want to verify:
>>
>>
>> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>> debian-9.8.0-amd64-netinst.iso
>>
>> More explicite is the hint to use program "sha512sum". A run of
>>
>> sha512sum debian-9.8.0-amd64-netinst.iso
>>
>> puts out
>>
>>
>> cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245
>> debian-9.8.0-amd64-netinst.iso
>>
>> which you should compare with the line in SHA512SUMS.
>>
>> Alternatively you could run
>>
>> sha512sum --check SHA512SUMS 2>/dev/null
>>
The STDERR redirection to the null device could be avoided by using
'--ignore-missing'.
$ sha512sum -c --ignore-missing <CHECKSUM-FILE>
The '--strict' option could also be used.
"The following five options are useful only when verifying checksums:
...
--ignore-missing don't fail or report status for missing files
...
--strict exit non-zero for improperly formatted checksum lines
..."
--
John Doe
[toc] | [prev] | [next] | [standalone]
| From | Steve McIntyre <steve@einval.com> |
|---|---|
| Date | 2019-04-29 19:40 +0200 |
| Message-ID | <xSipY-4Tj-5@gated-at.bofh.it> |
| In reply to | #207057 |
[ I often skim the debian-user list, but when I'm away on vacation or at a conference I'll miss things unless I'm directly CC:ed ] Thomas wrote: >Hi, > >Chris XX wrote: >> I was trying to Verify the authenticity of Debian CDs on your website, but I >> don't see instructions that will guide me through the process >> (step-by-step). > >(We are the users. But some Debian Developers are watching, too.) > >Obviously there is a gap between checksum file verification and .iso image >verification. > >Let's first look at the files offered for download: > https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/ >has among others ... > ... > Found: >0b0a75b8a0c8dc05a4b43273e44d7b5e3b0ecec6d9b4e1c88a95d9c886cba5ae0dbeb4b7a5a3016106096a9071572b9a3d8b54dd91a50abce15f713fa22ff229 > Expected: >cc4a6bd50925c1c4af98049060e304494bc9da61eb5eb272c556d67608de14d4e6a4b8bc1c9412a0f810083912e228569f3771ffffa7174538f3e26f45a05245 > MISMATCH: 'debian-9.8.0-amd64-netinst.iso' checksum differs from 'debian-9.8.0-amd64-netinst.iso' in 'SHA512SUMS' > >So you know that the checksumers really detect nearly all damages of >debian-9.8.0-amd64-netinst.iso. > >-------------------------------------------------------------------------- > >@ Steve McIntyre (maintainer of debian-cd): > >Do you agree with the instructions above ? Yes, that's a very clear description. Thanks! >Is there a consolidated wiki page with such instructions which i failed >to find ? If not: shall we make such a page ? I'm working with the web team to update our web pages for image download, and part of that will include a much clearer set of verification instructions. If you're happy for me to borrow your text above, I think it's a good start! -- Steve McIntyre, Cambridge, UK. steve@einval.com Armed with "Valor": "Centurion" represents quality of Discipline, Honor, Integrity and Loyalty. Now you don't have to be a Caesar to concord the digital world while feeling safe and proud.
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2019-04-29 20:20 +0200 |
| Message-ID | <xSj2F-5nc-1@gated-at.bofh.it> |
| In reply to | #207982 |
Hi, i wrote in https://lists.debian.org/debian-user/2019/04/msg00214.html > > > SHA512SUMS.sign [...] SHA512SUMS [...] debian-9.8.0-amd64-netinst.iso john doe wrote: > > $ sha512sum -c --ignore-missing <CHECKSUM-FILE> > > The '--strict' option could also be used. Steve McIntyre wrote: > If you're happy for me to borrow your text > above, I think it's a good start! I meanwhile discovered that i already wrote a more concise wiki paragraph about that issue: https://wiki.debian.org/JigdoOnLive#Verify_the_Debian_Live_download Especially this line gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS is obviously an improvement over mine in msg00214.html gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D gpg --keyserver keyring.debian.org --recv-keys 6294BE9B gpg --keyserver keyring.debian.org --recv-keys 09EA8AC3 gpg --verify SHA512SUMS.sign SHA512SUMS (In that wiki i propose to first verify the SHA512SUMS and afterwards the gpg signature. IIRC, i had in mind that transport damage of the ISO is more likely than transport damage of the SHA512SUMS file or malicious activities. Whether this is a valid idea stays undecided ... scratching head.) Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-04-06 12:30 +0200 |
| Message-ID | <xJQKd-2WA-7@gated-at.bofh.it> |
| In reply to | #207054 |
On 4/5/2019 10:26 PM, Chris XX wrote:
> I was trying to Verify the authenticity of Debian CDs on your website, but
What flavor of Debian do you want to instal?
What OS ("linux","Windows,""Mac") are you using to download "Debian"?
> I don't see instructions that will guide me through the process
> (step-by-step).
>
Answers to the above questions are required to be able to answer this
question.
This process is actualy in two folds:
- Insuring that the downloaded file is properly downloaded
- Verifying that the downloaded file has not been tampered with
To do that for a Debian file three files are needed:
- SHA512SUMS.sign
- SHA512SUMS
- Iso file
--
John Doe
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web