Re: trust update servers?



On Fri, 28 Sep 2007, birre wrote:-

On 2007-09-28 09:29, houghi wrote:

However it is very unlikely that a mirror will do
something like that.
houghi

But this _CAN_ happen one day, so importing the key from the mirror is
not the best thing to do. (even if we do it all the time)

Come up with a better method, get your new method added to bugzilla,
including any patches to help get them started, and it may be
implemented in 11.0 .

Hmm, I think I might have heard something similar to this mentioned
before in this group :)

The keys should be added from another server,
that can't be hacked at the same time, or at least a fingerprint check.

Or, if you're really paranoid, have it grab the same keys from multiple
different servers and ensure they're all the same.

This is something that maybe need to be added to some security checker.

See above :)


Regards,
David Bolt

--
Member of Team Acorn checking nodes at 100 Mnodes/s: www.distributed.net
RISC OS 3.11 | SUSE 10.0 32bit | SUSE 10.1 32bit | openSUSE 10.2 32bit
RISC OS 3.6 | SUSE 10.0 64bit | SUSE 10.1 64bit | openSUSE 10.2 64bit
TOS 4.02 | SUSE 9.3 32bit | | openSUSE 10.3b2 32bit
.



Relevant Pages

  • Re: Firefox 2.0
    ... Just add the mozilla project as an installation source from any ... mirror. ... I don't see that the mozilla project mirrors have firefox 2.0 yet. ...
    (alt.os.linux.suse)
  • Re: 9.3 is online
    ... On Mon, 27 Jun 2005, houghi wrote:- ... >> are these the full dvd 's then ... it looks like the 9.3 mirror is almost complete. ... Member of Team Acorn checking nodes at 63 Mnodes/s: http://www.distributed.net/ ...
    (alt.os.linux.suse)
  • Re: Firefox 2.0
    ... houghi wrote: ... Just add the mozilla project as an installation source from any ... mirror. ... I don't see that the mozilla project mirrors have firefox 2.0 yet. ...
    (alt.os.linux.suse)
  • Re: 10.1 & update to KDE3.5.2: 2 KDM processes running
    ... Houghi, did you even check the link I gave? ... You need to add the yast-source directory to the YaST source manager." ... mirror since 2002? ... mentioned server for a README...) ...
    (alt.os.linux.suse)
  • Errors on the REDHAT metadata
    ... While running "yum whatprovides" I received the following errors: ... Importing additional filelist information ... Trying other mirror. ...
    (Fedora)