SliTaz SliTaz Forum

You are not logged in.

#1 2016-07-12 11:16:02

AnhHuynh
Member
Registered: 2016-07-08
Posts: 23

Packages and ISO files's signature and verification

Hi,

The [c]tazpkg[/c] scripts download files from the (main) mirror and verify them using [c]md5[/c] method. This is very traditional and I think the packages can be easily modified by 3rd parties.

Is there any feature / plan to support more secure signature and verification methods? (Using GPG for example)

Thanks

Offline

#2 2016-07-15 03:46:37

hackdorte
Member
Registered: 2014-06-05
Posts: 83

Re: Packages and ISO files's signature and verification

See: /var/lib/tazpkg/packages.md5

Offline

#3 2016-07-16 06:55:40

AnhHuynh
Member
Registered: 2016-07-08
Posts: 23

Re: Packages and ISO files's signature and verification

@Hackdorte: Yes I see that file, but I don't think that is enough.

Offline

Registered users online in this topic: 0, guests: 1
[Bot] ClaudeBot

Board footer

Powered by FluxBB
Modified by Visman

[ Generated in 0.017 seconds, 7 queries executed - Memory usage: 1.53 MiB (Peak: 1.77 MiB) ]