Re: Debian package security

2001-10-02 Thread Manoj Srivastava
Hi, The Packages file for the corresponding section hold the MD5sum of the .deb files. For example, look at: (http://ftp1.us.debian.org/debian/dists/woody/binary-i386/Packages.gz) Now, how do you know that the Packages file was not tampered with? The top level Release file has

Debian package security

2001-10-02 Thread George Karaolides
Hi all, It seems to me that this message belongs here rather than on debian-security or debian-security-announce, but please correct me if I'm wrong. :) I am running Debian potato on a number of machines. I have downloaded potato from the net, and used apt-move to make a local mirror on one of