Re: Rpm-metadata Digest, Vol 16, Issue 5

Randy Zagar <[email protected]>
Newsgroups gmane.linux.rpm.metadata
Organization Applied Research Laboratories
Message-ID <[email protected]>
When you say that it "raises the bar sufficiently", you really ought to
add "for me" to the end of that sentence.  You probably aren't working
for the same set of clients that I am.  In addition to having paranoia
that "goes to 11" as a job requirement, I also have to consider that any
RPM-based system I deliver may be deployed for 20 years.  Given the
current state-of-the-art, and my rather unique customer requirements,
I'd prefer to follow the "tripwire" philosophy which is to never trust
any single signature or checksum.

Plus, I'm not sure what the rationale for opposing an SHA-1 field in the
xml file is based on...  Why aren't ALL rpm metadata fields being
supported in xml?  Wouldn't it be simpler to just say "we support all
metadata fields supported by RPM"?  That way there is no need to
"discuss" whether or not something gets included in the DTD.

Anyway, some of these questions are just rhetorical.  I just brought
this stuff up because I was looking at the sample xml files and didn't
see all the fields I expected to see.  Anyway, feel free to ignore my
rantings if you wish.  My needs are probably an edge-case anyway and I'm
certainly not paying your salary, so handle it how you want...

-RZ


On Mon, 2005-02-21 at 11:00, [email protected]
wrote:
> Message: 2
> Date: Sun, 20 Feb 2005 16:38:38 -0500
> From: Jeff Johnson <[email protected]>
> Subject: Re: [Rpm-metadata] Re: Rpm-metadata Digest, Vol 16, Issue 4
> To: [email protected]
> Message-ID: <[email protected]>
> Content-Type: text/plain; charset=us-ascii; format=flowed
> 
> seth vidal wrote:
> 
> >On Sun, 2005-02-20 at 13:02 -0600, Randy Zagar wrote:
> >  
> >
> >>What makes you think I'm joking?
> >>
> >>The RPMs themselves contain SHA-1, MD5 checksums and GPG signatures.
> >>
> >>Why shouldn't the XML metadata files contain all relevant software
> >>validation metadata?
> >>    
> >>
> >
> >Well, if you want to validate the pkgs you check gpg signatures, not
> >sha1sums or md5sums.
> >
> >so instead of just adding more data w/o any real use to the metadata it
> >would make more sense, to me, to work on gpg signing.
> >
> 
> FYI: The problems are inseperable, DSA is based on SHA-1. If you can
> create a SHA-1 hash collision, then you can spoof DSA.
> 
> Meanwhile, *please* don't include Yet Another Digest everywhere in 
> rpm-metadata,
> nor try to add duplicate md5+sha1 disgests. Even if SHA-1 collisions are 
> now know easier
> than what was originally thought, it's not exactly trivial to do, nor is 
> it going to be
> trivial to create a SHA-1 hash collision for quite some years yet (if ever).
> 
> And even then, having both MD5+SHA1 ain't the right answer, SHA257, or 
> SHA386 or SHA512
> raises the bar sufficiently.
> 
> 73 de Jeff
-- 
Randy Zagar <[email protected]>
Applied Research Laboratories

_______________________________________________
Rpm-metadata mailing list
[email protected]
https://lists.dulug.duke.edu/mailman/listinfo/rpm-metadata
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQBCGkPnKQP9Tvu8x8wRAralAJ9OAgZiYaDSo1JJ5YmkVkL4zEZWLwCdHLoH
GUfnBD/FXlC9DOu4qBmJ/QU=
=dOrD
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.