Re: securing a unix system - suggestions on checking for intrusions
Volker Kuhlmann <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu 06 Oct 2011 14:54:56 NZDT +1300, Robin Sheat wrote: > But, is it checking the sigs on the binaries, or just that the RPM you > installed was fine? For rpm that is the same thing. Before installing, it checks for signed packages whether the signatures matches a key on the rpm keyring, so there is a point in making sure all packages are signed. During installation it creates a database containing metadata incl hashes of all files, and all that metadata can be checked again afterwards. I don't know how difficult it would be to tamper with the database, but backing that up is trivial. Volker -- Volker Kuhlmann is list0570 with the domain in header. http://volker.dnsalias.net/ Please do not CC list postings to me. _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug