Re: Integrity check against package repository?

2013-04-30 Thread Paul Wise
On Tue, Apr 30, 2013 at 12:02 PM, Matthew Babcock wrote: Signed Zones would be expected and necessary of course but, I think that would be awesome. Both debian.org and debian.net domains are signed with DNSSEC. -- bye, pabs http://wiki.debian.org/PaulWise -- To UNSUBSCRIBE, email to

Integrity check against package repository?

2013-04-29 Thread adrelanos
Hi! When there are security updates, I review and install them as soon as possible and think about using automatic updates. From time to time I want to boot from a clean boot CD and check if the system has been compromised. For that reason, I want to check if any packages / binaries have been

Re: Integrity check against package repository?

2013-04-29 Thread Matthew Babcock
Hello Thank you for starting this thread!!! The command that you are referring to is (would be) a functional equivalent to Red Hat's rpm -v all command. Reference - I have looked into doing this in Debian and am very sad to see that there is no equivalent command in Debian, further

Re: Integrity check against package repository?

2013-04-29 Thread Paul Wise
On Tue, Apr 30, 2013 at 12:02 PM, Matthew Babcock wrote: So I was just looking around on a mirror, and it seems that Debian is already fixing this large problem. I say that because if you look at the InRelease file, it is signed. However, I do not see aptitude update retrieving the InRelease