-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
On 2018-05-26 14:25, haaber wrote:
>
>>> I just installed f27 in ins full and minimal template on Q4.0
>>> from the repos. When installing extra packages (for example
>>> sys-net tools) in f27-minimal the download works, BUT
>>> checksums fails. The point is that fucking dnf ignorantly
>>> installs the packages anyhow without putting any questions.
>>> Result: such a tempate is compromised right from the beginning,
>>> I will have to delete it without ever running it.
>>>
>>> The warning to all users is to NEVER run unattended (say,
>>> scripted) updates on fedora based templates since apparently
>>> they give a shit on security.
>>>
>> Checksums are only for integrity, not authenticity. For
>> security, PGP signature checking is what matters.
> @andrew: you are right, but if even checksums are ignored, pgp
> won't be considered either
What makes you say that? Is the PGP signature checking somehow
dependent on the checksum checking in dnf's code?
Anyway, _if_ you're right that dnf is failing to check signatures even
when `gpgcheck=1` is in the repo definition, then this is a critical
security bug that should be reported upstream immediately.
> ... and that IS an issue.
>
> @ awokd (on your question about re-downloads): I hope I was not
> complaining based on a misread and I would have liked to verify
> once more: too late for this time however, I had deleted the
> template this morning right away. I'll re-do it!
>
> Bernhard
>
iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlsJ5sYACgkQ203TvDlQ
MDBpnA//RDz0E6bysHQoRm/b8kbdv29Zx3PJNPUsdOdHbGa2tGGe3h6hS1F+4v1s
9RXUt23lONmLqOhxKi81S6BVArgZM37mFmf2rqzjd8G4+Dirw8gpisijrY5/AJM/
nx+9bBPXXRPrh/8oR9zBiktuUyrZB1OJPzBwSdi/Ss5Y0Pc3MoCi3ByChA54PsEt
laV/uWql1tJ75ZO3GMnTmdvqN2wFxuHabtQth4iUO3OH4c9okqh9cAo3T9bQvDTa
4/1Xehkz25861sRUqpcDXX5DjV674decIC3uUPXH8F6urml/qwouPJcSE3UPDjdz
WF5uK1400paVj5gPX/WcRi7BHghZ2yz7he2921n52ZlEUXTOAQb3J6iBC6rs7KcM
KdhkVb5jAjqV9fnK8UEtXlYqw8ZbkpelDHqoADfOvgBkC68cfuAZac06BdnxCVb2
qgOZgltuq2Z2u7KaXXD+jFf/jPPNT6QUgQ/OQspwgaQ3474ldGOYWcfSVCVbwBhU
mf1fBBQKXDvy99F89BKVb+VNTTA1tbUVxQ75d/6DJMlkSRX+lFN3LCie9hDP9lzc
9bnLspiPWAWF90tQZIYEVdSvOiJl/4sS/iw3ilszogtj8FD+hNiTGzQPgyuqdUr0
S9FgpB9j4ieteiESDmyr0awNiPh0iWRMaNHH7xltyYaU2HX06RY=
=TVMe
-----END PGP SIGNATURE-----