LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 12-10-2015, 07:07 PM   #1
stf92
Senior Member
 
Registered: Apr 2007
Location: Buenos Aires.
Distribution: Slackware
Posts: 4,442

Rep: Reputation: 76
Do .sig files contain information to check the integrity of files?


I downloaded the following files.
Code:
total 2260
-rw------- 1 bill bill 1428776 Dec  8 22:31 avr-libc-1.8.0.tar.bz2
-rw------- 1 bill bill      72 Dec  8 22:32 avr-libc-1.8.0.tar.bz2.sig
-rw------- 1 bill bill  127217 Dec  8 22:33 avr-libc-manpages-1.8.0.tar.bz2
-rw------- 1 bill bill      72 Dec  8 22:33 avr-libc-manpages-1.8.0.tar.bz2.sig
-rw------- 1 bill bill  725852 Dec  8 22:33 avr-libc-user-manual-1.8.0.tar.bz2
-rw------- 1 bill bill      72 Dec  8 22:34 avr-libc-user-manual-1.8.0.tar.bz2.sig
There are no .md5 files here. Do .sig files contain information to check the integrity of files, besides checking authenticity? A related question would be: don't .bz2 files contain error detection code?

Last edited by stf92; 12-10-2015 at 07:12 PM.
 
Old 12-10-2015, 07:40 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,323
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
Apparently they do include some means of integrity checking, though I've never used it. See this thread: http://www.linuxquestions.org/questi...g-file-259395/
 
1 members found this post helpful.
Old 12-11-2015, 06:08 AM   #3
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,897

Rep: Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019
Could also be an OpenBSD 'signify' signature file, which also uses a '.sig' filename suffix. Or, it could be anything else for that matter: what's in a filename?... But, most likely, it's a GPG unarmored detached signature.
 
Old 12-11-2015, 07:03 AM   #4
xflow7
Member
 
Registered: May 2004
Distribution: Slackware
Posts: 215

Rep: Reputation: 45
I believe if it's a GPG signature, the short answer is yes.

You can use gpg --verify to confirm the validity of the signature and the integrity of the file.

More here:

https://www.gnupg.org/gph/en/manual/x135.html

Last edited by xflow7; 12-11-2015 at 07:04 AM.
 
Old 12-11-2015, 09:07 AM   #5
mralk3
Slackware Contributor
 
Registered: May 2015
Distribution: Slackware
Posts: 1,900

Rep: Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050
Usually the project maintainer or lead developer will sign their source archives with a GPG key. Not only does this verify the file is not tampered with, it also verifies the origin of the file and who it was last edited by.

md5 and sha256 check sums only verify that a file has not been edited since that specific check sum was created. Which is why many open source projects provide a GPG signature as well as a md5 checksum. I've seen sha256sums used in place of md5sums in projects where integrity is of higher value.

It has been proven that data collisions are possible with the md5 algorithm, so many projects that require higher validity of their data use the sha256 algorithm instead.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
.sig files with .tar files... any real significance? porcelain Linux - Newbie 5 04-28-2010 06:49 AM
Using Mplayer to check a files integrity? fragged Programming 13 10-04-2009 04:46 PM
creating tar files with high data integrity edman007 Linux - Software 13 10-10-2006 02:00 PM
Bind and DNS information conf files and zone files aaronluke Linux - General 1 10-13-2002 09:41 AM
What are rpm.sig files? Rimmer Linux - General 3 07-19-2001 12:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 11:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration