Re: securing a unix system - suggestions on checking for intrusions
Bruce Kingsbury <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <CANWgrUGWtPCbS_2TgZswXdsOnFJqHb-yyckrmFy8gSP7eK5fqw@mail.gmail.com> |
Fairly sure deb can verify all the binaries installed by a package .. I think I had to do it once... -- sent from my Ideos On Oct 6, 2011 2:55 PM, "Robin Sheat" <[email protected]> wrote: > Op donderdag 06-10-2011 om 13:43 uur [tijdzone +1300], schreef Robin > Paulson: >> i would guess to check for suspicious files that have replaced files >> from the repo? i.e. ensuring you've still got the exact binary >> installed >> that you want/should have? > > But, is it checking the sigs on the binaries, or just that the RPM you > installed was fine? > > Actually, if every manifest contains the hash of each installed file, > and that manifest is signed, then it would be useful to verify the > integrity of those aspects of the system. > > But I don't think it's doing that. > > Robin. _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug