4 ms·
Btw rpm package manager keeps track of checksums of metadata and content for all installed packages, so that one can verify integrity of all (rpm -Va) or a part
by marbu 5y ago
Btw rpm package manager keeps track of checksums of metadata and content for all installed packages, so that one can verify integrity of all (rpm -Va) or a particular package (rpm -V foo) later.
- agumonkey 5y agoso IIUC it's an os level tripwire ?
- marbu 5y agoYes. But I guess that tripwire has more features.
- GordonS 5y agoAh, cool, I didn't know that. Do you know if it uses public key signatures, or if it's simply a list of known hashes for each file of each version?
- dfghdfgj 5y agoThis applies to almost all modern linux package managers. PGP is typically used to sign a collection of hashes (and other metadata). PGP is generally only used at package install/build time, and the subsequently installed/generated manifest is used when you ask the package manager to verify the package.
- marbu 5y agoIt just compares expected checksum from rpm database with actual state in the system. That said, rpm supports package signing, so that it can catch a package which was tampered with and prevent it's installation.