Re: trust update servers?



On Thu, 27 Sep 2007, takeout wrote:-

Just wondering, what kind of trust or authentication mechanism is used
by Yast Online Update? I know its some kind of public key system... When
I trust an update source and add it, am I trusting Suse/Novell, or just
that update server? Like I use mirrors.kernel.org. Am I trusting them or
are they just hosting files that are signed by the openSUSE team?

Why not check and see. The key you're going to be importing/trusting is
content.key . This just so happens to be exactly the same as the file
media.1/products.key, and also gpg-pubkey-9c800aca-40d8063e.asc .

To check it, all you need to do is import it into your own GPG key-ring.
If/when you do, you should see something like this:

davjam@adder:/local/temp> gpg --import gpg-pubkey-9c800aca-40d8063e.asc
gpg: key 9C800ACA: "SuSE Package Signing Key <build@xxxxxxx>" 2 new signatures
gpg: Total number processed: 1
gpg: new signatures: 2
gpg: 3 marginal(s) needed, 1 complete(s) needed, PGP trust model
gpg: depth: 0 valid: 1 signed: 0 trust: 0-, 0q, 0n, 0m, 0f, 1u


Regards,
David Bolt

--
Member of Team Acorn checking nodes at 100 Mnodes/s: www.distributed.net
RISC OS 3.11 | SUSE 10.0 32bit | SUSE 10.1 32bit | openSUSE 10.2 32bit
RISC OS 3.6 | SUSE 10.0 64bit | SUSE 10.1 64bit | openSUSE 10.2 64bit
TOS 4.02 | SUSE 9.3 32bit | | openSUSE 10.3b2 32bit
.



Relevant Pages

  • Re: PGPsigs: the Choice of Con Artists
    ... They can insist whatever they want to insist but if I trust none of them ... You seem to have two problems: one is that you don't like the PGP signature ... signature or break public key encryption. ...
    (comp.os.linux.misc)
  • Re: Secrecy and user trust
    ... Aldo Foot wrote, On 09/04/2008 12:10 PM: ... secure distribution channel. ... The public key really must be distributed in a secure manner. ... Now if some time earlier Jane and I had met, and exchanged public keys and she felt that my signature was worthy of trust[1], and I had signed your key before giving it to Jim, then Jane would have SOME reason to trust that the key came from _WHO_ it claims to come from instead of some key that Jim generated to do a MITM attack. ...
    (Fedora)
  • Re: New Method for Authenticated Public Key Exchange without Digital Certificates
    ... > certificates were redundant and superfluous when the relying party ... > context of the original posting) and the semantic meaning of trust ... > the addition of public key operations to these environments isn't to ... > operations are the financial institutions. ...
    (sci.crypt)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... That is say I trust Paul Rubin's public key. ... Paul likes the business so he signs their ... | 1) is the server i'm talking to really the server I think it is? ...
    (sci.crypt)
  • RE: how can you verify that the site you get is not a fake?
    ... > returns some information to me, the browser. ... The cert that you recieve from a website is signed with the ... public key because factoring very large ... kind of background check) by which a ca that you trust signs keys. ...
    (Fedora)