FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Debian > Debian KDE

 
 
LinkBack Thread Tools
 
Old 09-14-2010, 11:05 AM
Torsten Grote
 
Default KDE SC 4.5.1 packages available

On Tuesday 14 September 2010 13:01:24 George Kiagiadakis wrote:
> > WARNING: untrusted versions of the following packages will be installed!
> > Untrusted packages could compromise your system's security.
> >
> > Have the packages been properly signed? Is anybody else having this
> > problem?
>
> Try running aptitude/apt-get update again.

It works now!

Thanks for the quick fix!

Torsten


--
To UNSUBSCRIBE, email to debian-kde-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201009141305.51402.Torsten.Grote@gmx.de">http://lists.debian.org/201009141305.51402.Torsten.Grote@gmx.de
 
Old 09-14-2010, 04:30 PM
Modestas Vainius
 
Default KDE SC 4.5.1 packages available

Hello,

On antradienis 14 RugsÄ—jis 2010 13:09:37 Torsten Grote wrote:
> Another note on security:
> pkg-kde-archive-keyring seems to be hosted on the same repository it is
> supposed to verify the trustworthiness of and it is not signed with an
> already trusted key. Installing an untrusted key and trust that for all
> KDE packages is pointless for security.

Well, frankly, pkg-kde-archive-keyring is not a very good example of security,
but imho it is good enough for this purpose. It is there mostly to shut
apt/aptitude up. Have in mind that you already trust the repository enough by
adding it to sources.list.

However, you are still somewhat protected from man-in-the-middle attacks. The
archive key is signed by me and my key is in the debian developers keyring so
you can always validate pkg-kde-archive-keyring package.

$ gpg --no-default-keyring --keyring /usr/share/keyrings/pkg-kde-archive-
keyring.gpg --list-sigs E79C8BAB
pub 4096R/E79C8BAB 2010-03-05
uid Debian pkg-kde repository signing key (http://pkg-
kde.alioth.debian.org/) <debian-qt-kde@lists.debian.org>
sig 3 E79C8BAB 2010-03-05 Debian pkg-kde repository signing key
(http://pkg-kde.alioth.debian.org/) <debian-qt-kde@lists.debian.org>
sig 73EAE214 2010-03-05 [User ID not found]


--
Modestas Vainius <modestas@vainius.eu>
 
Old 09-14-2010, 04:41 PM
David Baron
 
Default KDE SC 4.5.1 packages available

Versions are on Debian "experimental snapshots" as 4.5.1-or1


--
To UNSUBSCRIBE, email to debian-kde-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201009141841.31485.d_baron@012.net.il">http://lists.debian.org/201009141841.31485.d_baron@012.net.il
 

Thread Tools




All times are GMT. The time now is 08:52 PM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright ©2007 - 2008, www.linux-archive.org