Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Jun 1997 16:45:01 -0400 (EDT)
From:      Garrett Wollman <wollman@khavrinen.lcs.mit.edu>
To:        Garrett Wollman <wollman@khavrinen.lcs.mit.edu>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Attempt to compromise root
Message-ID:  <199706202045.QAA02968@khavrinen.lcs.mit.edu>
In-Reply-To: <199706201909.PAA02705@khavrinen.lcs.mit.edu>
References:  <33AAB0CA.2781E494@fsl.noaa.gov> <199706201909.PAA02705@khavrinen.lcs.mit.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
<<On Fri, 20 Jun 1997 15:09:16 -0400 (EDT), I wrote:

> There already is such a thing.  Every recent release includes mtree
> files with md5 digests of everything included in the distribution.
> See the FTP site or CD-ROM.

I forgot to mention....

Probably the release engineer should generate and publish a digital
signature of the files and the distribution's associated
CHECKSUMS.MD5.  Actually, the installation system ought to be able
itself to at least verify the MD5s of the tarballs it retrieves.

-GAWollman

--
Garrett A. Wollman   | O Siem / We are all family / O Siem / We're all the same
wollman@lcs.mit.edu  | O Siem / The fires of freedom 
Opinions not those of| Dance in the burning flame
MIT, LCS, CRS, or NSA|                     - Susan Aglukark and Chad Irschick



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199706202045.QAA02968>