discontinuing rsync service on security.debian.org

2019-11-15 Thread Julien Cristau
Hi,

For a long time, the Debian security mirrors have served the security
archive via both HTTP and rsync.  As part of improving the reliability
of security.debian.org for our users, the Debian mirrors team is going
to separate those services to different host names:
- http://security.debian.org/debian-security/ will remain the entry
  point for HTTP clients such as apt
- rsync://rsync.security.debian.org/debian-security/ is now
  available for users and organizations who wish to mirror the entire
  security archive.  (Though as noted at
  https://www.debian.org/mirror/ftpmirror#what we do *not* recommend
  doing this.)

rsync service on security.debian.org will stop in the near future (some
time after the end of this month), and we encourage anyone relying on it
to migrate to the new host name as soon as possible.

Thanks,
Julien, for the Debian mirrors team


signature.asc
Description: PGP signature


debcheckroot v2.0 released

2019-11-15 Thread Elmar Stellnberger

Dear readers of debian-security

  I have just released debcheckroot-v2.0: 
https://www.elstel.org/debcheckroot/


The new tool can be used to check a Debian installation also against 
previously unknown rootkits. It has many improvements towards 
debcheckroot-v1.0:


# usage of direct comparison or creation and usage of sha-256 lists 
instead of the unsafe md5sums provided in the package header
# allow usage of multiple changeable media: i.e. DVD & BD-SL verification 
rather than just BD-DL verification

# testing of symbolic links, of user, group and file-mode
# scanning the home directory for odd filenames that contain control 
characters, on request: listing all hidden binary files in the home 
directory
# download only mode + shuffling of download order for package download 
via Tails/Tor and subsequent offline verification
# use of Python3 instead of Perl with built in support for tar, xzip, gzip 
and bzip2; no more external helper programs required, works from any 
live cd!


Finally debcheckroot-v1.0 did no more work with current versions of 
Debian as Debian now uses xzip instead of gzip. The new program supports 
any of xzip, gzip and bz2 for compression of the data.tar.xz and the 
controls .tar.xz inside the .deb ar-archive. Files are merely unpacked 
in memory so debcheckroot keeps being quite efficient.


I would be happy to discuss the new release here or to assist anyone who 
wants to test the new tool!


Regards,
Elmar