LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel
User Name
Password
Linux - Kernel This forum is for all discussion relating to the Linux kernel.

Notices


Reply
  Search this Thread
Old 02-21-2012, 11:08 PM   #1
quiescere
Member
 
Registered: Sep 2003
Distribution: Slackware64 14.2
Posts: 54

Rep: Reputation: 15
Why aren't GPG sigs linked on the front page of kernel.org?


Title says it all. You can download full source, patches, changelogs, whatever for multiple versions directly from the front page of kernel.org. However, if you want to the GPG sig of the source, you have to click down into the archives. I assume there must be a sound reason for this, but for the life of me I cannot figure out what it is.

Not linking the signing key[s] I understand, but why not the sig?

I emailed kernel.org to ask, and was told to read
http://www.kernel.org/signature.html
which was supposedly linked from the FAQ. Well,
  1. this page does not seem to answer my question, and
  2. it's not actually linked from FAQ, either.

Thanks,
quiescere
 
Old 02-22-2012, 12:12 PM   #2
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
Well since this isn't kernel.org, why not send them an e-mail and ask them?
 
Old 02-22-2012, 02:04 PM   #3
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
I agree NyteOwl, in fact, it bothers me too, so I will also e-mail them.
 
Old 02-22-2012, 04:17 PM   #4
quiescere
Member
 
Registered: Sep 2003
Distribution: Slackware64 14.2
Posts: 54

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by NyteOwl View Post
Well since this isn't kernel.org, why not send them an e-mail and ask them?
From my original post starting the thread:
Quote:
I emailed kernel.org to ask
As the response was unhelpful, I turned here hoping more eyes meant more time for a thoughtful reply.
 
Old 02-22-2012, 04:23 PM   #5
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
@quiescere: The folks you were/are communicating with are likely overworked and absurdly busy.

I agree that it sounds like their reply didn't address your question. And your point is a good one: pubkeys (to verify signatures) should probably be more prominently displayed and more easily discovered.

You might reply again to the thread you've already started with them. Use clear, succinct English, and request an actionable item.

Good luck pursuing it further.

-------

Edited to add: the keys are actually linked to on the front page. But they're way, way below the fold. You have to scroll down to see them. See attached PNG for a screenshot.
Attached Thumbnails
Click image for larger version

Name:	sig-note.png
Views:	11
Size:	42.4 KB
ID:	9131  

Last edited by anomie; 02-22-2012 at 04:28 PM.
 
Old 02-22-2012, 07:43 PM   #6
quiescere
Member
 
Registered: Sep 2003
Distribution: Slackware64 14.2
Posts: 54

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by anomie View Post
Edited to add: the keys are actually linked to on the front page. But they're way, way below the fold. You have to scroll down to see them. See attached PNG for a screenshot.
anomie, I sincerely appreciate the attention you've given my question, but this is still not quite what I am asking. I'm not as concerned about the public keys, which only need to be retrieved once. It's the signature files that must be downloaded with each new kernel version that interest me.
 
Old 02-23-2012, 10:50 AM   #7
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Ah, gotcha. The signed MD5 / SHA1 / whatever digests of the kernel. Yes, that's just as important as the keys themselves if you wish to verify the kernel you're downloading hasn't been tampered with.
 
Old 02-23-2012, 10:56 AM   #8
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quote:
Originally Posted by anomie View Post
Ah, gotcha. The signed MD5 / SHA1 / whatever digests of the kernel. Yes, that's just as important as the keys themselves if you wish to verify the kernel you're downloading hasn't been tampered with.
Yes, especially important since kernel.org got hacked a while back.

I also would like to know more about the hack, but no info was released on it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
GPG: Bad session key gpg between gpg on linux and gpg gui on windows XP konqi Linux - Software 1 07-21-2009 09:37 AM
On the front page. MikeZila LQ Suggestions & Feedback 2 11-11-2004 08:35 AM
Latest Kernel script on front page, does it need to be updated to accept four digits? SBing LQ Suggestions & Feedback 1 09-09-2004 12:35 PM
Anyone use Seahorse front-end for gpg? ArthurDent Linux - Software 1 06-03-2004 12:21 PM
front page jag2000 Linux - Software 3 05-23-2004 06:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel

All times are GMT -5. The time now is 07:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration