Stranica: 1/1.

SecureApt pomoć

Postano: 13 srp 2011, 16:49
Postao/la sumski
Bog ljudi! Planiram si napravit mini repozitorij , al neznam kak to točno napraviti , a da repo bude potpisan. Gledal sam wiki , ali nije bi baš pošlo za rukom , pa ako ko zna kak bi se to napravilo, cijenil bi pomoć. ;)

Re: SecureApt

Postano: 13 srp 2011, 17:36
Postao/la shrike
Smijem li pitati kakve veze ima naslov sa sadržajem?

Re: SecureApt

Postano: 13 srp 2011, 17:57
Postao/la sumski
Smiješ :)
NAME
apt-secure - Archive authentication support for APT

DESCRIPTION
Starting with version 0.6, apt contains code that does signature checking of the Release file for all archives.
This ensures that packages in the archive can't be modified by people who have no access to the Release file
signing key.

If a package comes from a archive without a signature or with a signature that apt does not have a key for that
package is considered untrusted and installing it will result in a big warning. apt-get will currently only warn
for unsigned archives, future releases might force all sources to be verified before downloading packages from
them.
Makar , naslov i je malko nezgodno stavljen...

Re: SecureApt pomoć

Postano: 13 srp 2011, 18:24
Postao/la glaskoncILLa
zapeo si sa postavljanjem repozitorija ili "osiguranjem"?
odnosno sto si dosad napravio?

Re: SecureApt pomoć

Postano: 13 srp 2011, 18:32
Postao/la sumski
Pakete :D
i packages.gz

Re: SecureApt pomoć

Postano: 13 srp 2011, 18:37
Postao/la glaskoncILLa
dakle imas pristup nekom web ili ftp serveru?

Re: SecureApt pomoć

Postano: 13 srp 2011, 18:41
Postao/la sumski
Za sad slažem lokalno dok ne vidim gdi ga točno budem stavil
ovak izgleda sources.list:

Kod: Označi sve

deb file::///Src/DEBS ./
Uglavnom , trebam "potpisat" packages i release file?
Jel lupam samo gpg --sign Packages/Release ili treba još kaj?

Re: SecureApt pomoć

Postano: 13 srp 2011, 18:46
Postao/la glaskoncILLa
Create a toplevel Release file. if it does not exist already. You can do this by running apt-ftparchive release (provided inftp apt-utils).
Sign it. You can do this by running gpg -abs -o Release.gpg Release.
Publish the key fingerprint, that way your users will know what key they need to import in order to authentic