Using the --verify option on cpanm
[email protected] (Abhijith Chandrashekar) Fri, 18 Jul 2014 00:17:59 +0000
| Newsgroups | perl.cpan.discuss |
|---|---|
| Message-ID | <[email protected]> |
--_000_194B822ED0D30F40885681F4E05045C9701D36SJCPEX01CL02citri_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Hello,
I intend to use cpanm to download perl modules into a secure environment th=
at is guarded by firewalls and have a couple of questions on how to do that=
.
a. I want to be able to verify the perl module that has been download=
ed by its signature. Cpanm provides an option for this called -verify, but =
the description for the option is a little ambiguous -
--verify
Verify the integrity of distribution files retrieved from PAUSE using CHECK=
SUMS and SIGNATURES (if found). Defaults to false.
It sounds like it means that the signature will be checked only if it is pr=
esent. If the --verify option is used and the signature is missing, will th=
e package be downloaded and installed nonetheless?
b. How does one obtain the public key that is used to check these sign=
atures? Is it installed along with cpanm?
Please let me know if this is not the appropriate mailing list to pose thes=
e questions. Appreciate any help.
Thanks,
Abhi
--_000_194B822ED0D30F40885681F4E05045C9701D36SJCPEX01CL02citri_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Helvetica;
panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
{font-family:SimSun;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:SimSun;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"\@SimSun";
panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1827164616;
mso-list-type:hybrid;
mso-list-template-ids:-1227818640 67698713 67698713 67698715 67698703 6769=
8713 67698715 67698703 67698713 67698715;}
@list l0:level1
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level4
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level7
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Hello,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">I intend to use cpanm to download perl modules into =
a secure environment that is guarded by firewalls and have a couple of ques=
tions on how to do that.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l0 level=
1 lfo1"><![if !supportLists]><span style=3D"mso-list:Ignore">a.<span style=
=3D"font:7.0pt "Times New Roman""> &=
nbsp;
</span></span><![endif]><span dir=3D"LTR"></span>I want to be able to verif=
y the perl module that has been downloaded by its signature. Cpanm provides=
an option for this called
<i>–verify</i>, but the description for the option is a little ambigu=
ous –<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal" style=3D"margin:3.75pt;text-indent:32.25pt;line-heig=
ht:15.0pt;background:white">
<b><span style=3D"font-size:12.0pt;color:#1F497D">--verify<o:p></o:p></span=
></b></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:3.75pt;margin-right:7.5p=
t;margin-bottom:3.75pt;margin-left:39.75pt;line-height:15.0pt;background:wh=
ite">
<span style=3D"font-size:12.0pt;color:#1F497D">Verify the integrity of dist=
ribution files retrieved from PAUSE using CHECKSUMS and SIGNATURES (if foun=
d). Defaults to false.</span><span style=3D"font-family:"Helvetica&quo=
t;,"sans-serif";color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">It sounds like it means t=
hat the signature will be checked only if it is present. If the --verify op=
tion is used and the signature is missing, will the package be downloaded a=
nd installed nonetheless?<o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l0 level=
1 lfo1"><![if !supportLists]><span style=3D"mso-list:Ignore">b.<span style=
=3D"font:7.0pt "Times New Roman"">
</span></span><![endif]><span dir=3D"LTR"></span>How does one obtain the pu=
blic key that is used to check these signatures? Is it installed along with=
cpanm?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Please let me know if this is not the appropriate ma=
iling list to pose these questions. Appreciate any help.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Thanks,<o:p></o:p></p>
<p class=3D"MsoNormal">Abhi<o:p></o:p></p>
</div>
</body>
</html>
--_000_194B822ED0D30F40885681F4E05045C9701D36SJCPEX01CL02citri_--