Hi!

The following packages in cooker are currently not signed by Mandrake:

gnome-vfs-1.0.4-4mdk.i586.rpm: md5 OK
gnome-vfs-extras-0.1.3-2mdk.i586.rpm: md5 OK
libclanlib1-vorbis-0.5.1-5mdk.i586.rpm: md5 OK
libgnome-vfs0-1.0.4-4mdk.i586.rpm: md5 OK
libgnome-vfs0-devel-1.0.4-4mdk.i586.rpm: md5 OK
locales-vi-2.3.1.2-8mdk.i586.rpm: md5 OK
mgetty-viewfax-1.1.28-2mdk.i586.rpm: md5 OK
mgetty-voice-1.1.28-2mdk.i586.rpm: md5 OK
pango-viewer-0.24-1mdk.i586.rpm: md5 OK
xmms-more-vis-plugins-1.5.0-2mdk.i586.rpm: md5 OK
xmms-more-vis-plugins-unsafe-1.5.0-2mdk.i586.rpm: md5 OK

Also, many rpms in contrib are also not signed (no list here, there are 
too much).

I think this is an important issue, because it is the only way we can tell 
that nobody changed the packages to introduce some virus or backdoor or 
whatever.

I also hope that after 8.2 is released, urpmi/rpmdrake will be enhanced to 
check the signatures and refuse installing packages without or an unknown 
signature.

Thanks.

-- 
   Michael Reinsch <[EMAIL PROTECTED]>                       http://mr.uue.org
------------------------------------------------------------------------

Reply via email to