Re: securing a unix system - suggestions on checking for intrusions

Volker Kuhlmann <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
On Thu 06 Oct 2011 14:54:56 NZDT +1300, Robin Sheat wrote:

> But, is it checking the sigs on the binaries, or just that the RPM you
> installed was fine?

For rpm that is the same thing. Before installing, it checks for signed
packages whether the signatures matches a key on the rpm keyring, so
there is a point in making sure all packages are signed. During
installation it creates a database containing metadata incl hashes of
all files, and all that metadata can be checked again afterwards. I
don't know how difficult it would be to tamper with the database, but
backing that up is trivial.

Volker

-- 
Volker Kuhlmann			is list0570 with the domain in header.
http://volker.dnsalias.net/	Please do not CC list postings to me.

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.