4 ms·
Is installing openbsd securely possible using hash checks and signing?
by farawayea 12y ago
Is installing openbsd securely possible using hash checks and signing?
- Spidler 12y agoYes, they have tools for that these days.
- brynet 12y agoOpenBSD 5.5 and 5.6 include signify(1) for both signing and verifying signed files. http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man1/signify.1?query=signify&sec=1 http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man1/...
- farawayea 12y agoWhat is the secure install process? Are there signatures for packages and for the iso file? The system wants to be secure, but it's not teaching me how to install it securely. Buying the CDs is risky. How can I know they're not backdoored?
- tedunangst 12y agoRead the install docs and search for "sign". http://ftp.openbsd.org/pub/OpenBSD/5.6/amd64/INSTALL.amd64 http://ftp.openbsd.org/pub/OpenBSD/5.6/amd64/INSTALL.amd64
- cesarb 12y agoForgive me if I'm missing something, but I don't see how to "bootstrap" the trust from an existing, non-OpenBSD system. For instance, for Fedora, the download page I use (https://fedoraproject.org/pt_BR/get-fedora https://fedoraproject.org/pt_BR/get-fedora) has a link on the sidebar to https://fedoraproject.org/pt_BR/verify https://fedoraproject.org/pt_BR/verify, which has a link to https://fedoraproject.org/pt_BR/keys https://fedoraproject.org/pt_BR/keys, which has the full fingerprint for the GPG keys. That page is authenticated via TLS. So, for me the trust chain for the Fedora installation DVD is: - The trust chain root is my current browser (a recent enough version of Firefox); - The browser trusts the CAs in its certificate store (the built-in CA certificates from Mozilla, plus the ICP-Brasil CA certificates); - One of these CAs verifies the certificates for the fedoraproject.org pages; - From these pages, I download a set of public GPG keys, and if I want I can verify their fingerprints; - The torrent for the installation DVD has the DVD image and a checksum file. I use GnuPG to verify the signature on the checksum file, and check the page to confirm that it was signed with the correct key; - Finally, I verify the SHA256 of the DVD image and confirm that it matches the value found in the checksum file. I don't know how I would do it for OpenBSD. The www.openbsd.org page doesn't seem to be available over TLS, so I can't use the CAs trusted by my browser to bootstrap the trust chain. If I had OpenBSD 5.5 installed, I could use it as the root of the trust chain (as explained at the link you posted), but unfortunately I don't have it installed anywhere, so that trust path doesn't work for me. If I had an OpenBSD 5.6 ISO in hand right now, what could I do to authenticate it? (Assume I have a recent Linux or BSD system to start with.)
- cowabunga 12y agoThe official way of doing this is to buy the CD set in which the code and keys are sent via different channels. You buy the CD set and it is mailed to you. You then verify that against the key on the web site. If the verification fails, either the CD set or the key is compromised. I really wouldn't trust a CA or shared PKI to do this to be honest as that means you have to trust three or more parties rather than just two.
- farawayea 12y agoThis mailing of cds seems silly. An attacker could compromise the cds to be different and serve you another signature on the site. This is easy for me to do. It must be the same for others.
- tedunangst 12y agoIt's easy for you to intercept somebody's mail and internet connection? Who do you work for?
- farawayea 12y agoNetworks are easy to attack if you have control over the ISP. Mail can be easily replaced by one single person monitoring someone's mail. A company where employees get their mail at work and only access the net from work could do both easily. I don't have resources for something like this, but doing this isn't as difficult as it might seem. A big enough adversary with enough resources could compromise everything used in security sensitive environments. I wanted to know if anything changed in how OpenBSD can be installed securely. It is easier to obtain other operating systems securely. They are less secure, but the authenticity of the iso files can be verified via signatures. This uncertainty has stopped me from using OpenBSD in the past. I have the same questions now. This is a question about obtaining an iso file to install OpenBSD knowing it's what the developers sent out, just like checking a sha256 signature for other operating systems when downloading. It's not a question about using it in a government agency. Thanks for the replies. You probably have more useful things to do than discuss this.