Cryptographic signatures of installer sets

Nathan Dorfman <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
Hello all,

I really hope I'm missing something here, and we can all have a nice
chuckle at my expense.

But I can't see any way the integrity of the installer sets (base.txz,
kernel.txz and friends) can be verified cryptographically? There is a
MANIFEST file containing SHA256 checksums, but it itself does not appear
to be signed in any way.

The installer images do come with PGP-signed checksums. So, when using
an image that already contains all the sets, one can be sure they are
authentic. What happens when one uses a network-only installer, though?
How can it authenticate the sets it downloads from the user's chosen
mirror?

A cursory glance at src/usr.sbin/bsdinstall suggests that it does not,
in fact, do that. Checksums are compared against the MANIFEST (in
scripts/checksum), but that is itself simply downloaded from the same
mirror (in scripts/jail), usually over plain FTP, without any
authentication.

Thanks,
-nd.
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.