Re: Debian sources have limited file integrity
Luke <[email protected]>
| Newsgroups | gmane.linux.debian.devel.www |
|---|---|
| Message-ID | <[email protected]> |
On 11/12/2016 09:39 PM, Luke wrote: > Hello, > Many downstream projects are using your source files directly from your > FTP and packaging. This presents a problem. > > 1) Navigate to https://ftp.de.debian.org/debian/pool/main/ > 2) Click on ANY folder/subfolder of a popular project. > 3) The only checksum can be found in the .dsc file. > > While having the .dsc file is better than nothing, it does not allow > downstream to run GPG verification against the source files themselves. > Additionally, .dsc files only have SHA256 as the strongest checksum. > SHA1 and MD5 have been considered weak/broken for some time, per > Debian's own documentation. > > Please consider implementing a system similar to kernel.org's - > https://mirrors.kernel.org/sourceware/lvm2/releases/ > > In this scenario, each source tarball is signed with GPG, and a > SHA512SUM is included for the entire directory as well. Downstream can > then verify the GPG signature and the checksum easily. > > Thank you for your time and concern. > > > Sincerely, > Luke > Parabola GNU/Linux-libre Packager > > Hello, I forgot to mention - HTTPS is also not properly functioning on ftp.debian.org. Please consider adding HTTPS support as soon as possible. Thank you. Sincerely, Luke Paraboal GNU/Linux-libre Packager
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJYKJr2AAoJEMP0/88+roaXOpIP/19gPNA5O56CtDXOGQ+hoaPM B+13JkssFJcF+Pd9T2v/8j2uCQrLf/e9+SG/kR6/RyZCHnvDIHaP7jOeNPx8wN9G Agt9nK9Q2g9ulHgyKxKniu4p2MHyfEwerQ+kieGL63FmjYemFAI3JCb3J0OZuZIZ JQ8oZB2HoXfd0Sguz36F8Fs5QogGQpjWmDY8brPr+kJmDX4flygByWNyZWMT/m7v FGefMvCJQy5A8aJGAz1e/EA9Ir4L1nuVhsVIzJNuZgl8nP021lfRYOxkTS/40J/A MOj64UjeBZlbKwPlFoskohr0tNuN5MMA/mFGL5ggv5YuJQgZYvWE7N3eB9w/Mjbr cItu81wJk0C3r2m0qQYscWlHo/mM+lhNb32mLjeNZx8WgFGhN7Xt2VSRRpfw4MFZ gcAv/SwDsfAuCsVLhBLpTLfIJ8XC8a7kbfRzmn/tip1PAN9ZybEhgnbg4HrEppjc ubsxwzCyonq9e0eG5I7+3jOuiMLdjIL8uNUdCFQ150qzZen/YpayARW+z8vJsJxo SpKY/fRulGfUVAOWkmNMggB3C4n3bQO3D8LAW9Oj8LdYb1rOZ6KKRxLekGpJjWRf qTuO5dkJu7iKPFwyRTvO9NWwCu8LXO+05e1/6fIINGQOpTzVyoT3WQZCO+teb9Gf DLnSaHkXIlo5vWsOAUGF =S6tV -----END PGP SIGNATURE-----