Thank You for Your time and answer, (sorry for long reply) Boyd:

>Depends on how you got the package.  There is a "chain of trust" between 
>your apt keyring and the package contents.  The Release and Packages files 
>have detached signatures, which APT verifies to ensure they are trusted and 
>not corrupt.  The Packages file contains multiple hashes for each .deb 
>package, which APT verifies to ensure they are trusted and not corrupt.  The 
>.deb package might contain a .debsums file.  If not .debsums can be 
>generated locally.

When does apt checks the package integrity: at download or at install moment? - 
If at install moment - then can I download w/ the help of wget and then put 
into apt's package dir. so that it will install as if it was retrieved by apt 
but not installed. Or apt will suppose id a package is there- then it is 
verified already and will not test its integrity?

The, at the time of checking apt relies on keyring, then it generates checksums 
- why do I need them, if apt already has checked the package?


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to