Re: Arch Linux security is still poor....

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Tue, Mar 16, 2010 at 12:18 PM, Jared Casper <jaredcasper@xxxxxxxxx> wrote:
> On Tue, Mar 16, 2010 at 8:49 AM, Aaron Griffin <aaronmgriffin@xxxxxxxxx> wrote:
>> On Tue, Mar 16, 2010 at 12:32 AM, Nilesh Govindarajan <lists@xxxxxxxxxx> wrote:
>>> I don't think we need any security team for Arch. New packages are
>>> released within a week of their updates. GPG signing and md5sum
>>> verification is a must though.
>>
>> md5sum verification has ALWAYS been done
>>
>
> In a security context, verification of files installed by a package
> _after installation_ would be nice.  i.e. "pacman --verify
> /usr/sbin/sshd" would tell me if the md5sum (or sha1sum, etc) of my
> /usr/sbin/sshd matches that of the official package.

Is this a feature request in the bug tracker? Please add it if you
want this functionality. That's the only way it will ever happen


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux