Alexandros Papadopoulos <[EMAIL PROTECTED]> schrieb:
> debsums: no md5sums for ssh

cant reproduce this one. Package ships with md5sums on sarge here.

> So I believe the above output NOT to be the result of a breach. My
> question is, is it acceptable to have so many important and widely
> used packages in *stable* without MD5 checksums?

you cant trust debsums anyway, since the files containing the md5 hashes are
not signed.

> Secondly, how can one fix this on a production system? Is the
> following method proposed by  Paul Gear @
> http://lists.debian.org/debian-security/2005/06/msg00126.html the
> best/only way?

newer debsum versions support creation of sums for packages which do not ship a
md5sum file. 

"debsums can generate checksum lists from deb archives for packages that don't
 include one."

bye,
        - michael


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to