Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution

Ken Dyke <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <1034273404.1534.145.camel@FatBoy>
On Thu, 2002-10-10 at 11:36, Sam Halliday wrote:
> On 10 Oct 2002 10:35:43 -0600 Ken Dyke <[email protected]>
> wrote:
> > /being too lazy to look
> > Is there a hint/pointer to a HOWTO for folks who don't know how 
> > to check the signature of a file?
> 
> first get their gpg key, and register it in your personal list of keys
> with
> gpg --import <their key>
> 
> then do the verify;
> gpg --verify <file>
> 
> OR, you dont need to do the key install if you just want to chekc the
> Primary key fingerprint on the verification against the known one.

I know how.  And now it is in the mail archives if it wasn't before.
Files can also be checked with

md5sum foo.bar

then check the hash against the published md5 signature.  The md5
checksum for gnupg can be found on http://www.gnupg.org/download.html

My point however is where/if we tell newbies how.

Additionally, I did not recall seeing a gnupg install hint or chapter in
blfs.

-- 
I think, therefore, ken_i_m
Chief Gadgeteer,
Elegant Innovations

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.