Re: One for the Security Guru's

Florian Weimer (Weimer@CERT.Uni-Stuttgart.DE)
Wed, 06 Nov 2002 22:39:18 +0100


James Cleverdon <jamesclv@us.ibm.com> writes:

> Be surprised: I run "gpg --verify foo.tgz.sign foo.tgz" every time I download
> from kernel.org. And, "rpm --checksig *.rpm" on stuff from redhat.com too.
>
> Given the recent trojaned source packages, I recommend that everyone do the
> same.

Aren't the signatures on kernel.org automatically generated?

-- 
Florian Weimer 	                  Weimer@CERT.Uni-Stuttgart.DE
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-685-5898
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/