LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 02-29-2016, 11:29 AM   #1
vvajrav
LQ Newbie
 
Registered: Feb 2016
Posts: 1

Rep: Reputation: Disabled
which is the best utility to embed digital signature in tar archive?


Hello

Please can someone share the list of utilities available to embed a digital signature in a .tar.gz file.

I have been using gpg so far with detach-sign option that generates a detached signature but now the intent is to create an archive and embed a signature within the same. Unlike GPG i don't want to either maintain a seperate file (like .asc) or save it with different ext (like .tar.gz.sig)

Kindly advise.
 
Old 03-01-2016, 04:50 AM   #2
Michael Uplawski
Senior Member
 
Registered: Dec 2015
Posts: 1,622
Blog Entries: 40

Rep: Reputation: Disabled
Quote:
Originally Posted by vvajrav View Post
Hello

Please can someone share the list of utilities available to embed a digital signature in a .tar.gz file.

I have been using gpg so far with detach-sign option that generates a detached signature but now the intent is to create an archive and embed a signature within the same. Unlike GPG i don't want to either maintain a seperate file (like .asc) or save it with different ext (like .tar.gz.sig)

Kindly advise.
The PKI-package comes with utilities that should do what you want.

But in view of the weaknesses of the X 509 standard, in your place, I just packed once again the original archive together with the GnuPG signature. If your users find this awkward, tell them that they are.
 
Old 03-01-2016, 07:17 AM   #3
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,882
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
Quote:
Originally Posted by vvajrav View Post
the intent is to create an archive and embed a signature within the same.
tar creates an archive, and can embed any file within that archive.

Create your digital signature file and then add it to your tar archive, using tar.
 
Old 03-01-2016, 09:19 AM   #4
Michael Uplawski
Senior Member
 
Registered: Dec 2015
Posts: 1,622
Blog Entries: 40

Rep: Reputation: Disabled
Quote:
Originally Posted by rtmistler View Post
tar creates an archive, and can embed any file within that archive.

Create your digital signature file and then add it to your tar archive, using tar.
The problem being, when you include the signature in the tar after having signed the tar... the resulting tar file is not the signed tar-file...
Put another way: Someone who returns from work late in the evening or someone who has not yet got his second coffee might try to test a signature on the *original* tar-file after having extracted only the signature (as a copie). This attempt has to fail.

Signing files selectively, -only a few of them that you consider important-, could be a solution. I prefer the approach that I mentioned above : Sign your tar file and put the signature together with the tar file *inside* another archive. This is so simple to comprehend that even half asleep, I might get the right idea when confronted to such a file.

Others will say, it lacks sophistication.

Last edited by Michael Uplawski; 03-05-2016 at 01:50 AM. Reason: cosmetics and bizarre grammer made less bizarre
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Tar - find editors and add to tar archive sumncguy Linux - Newbie 4 10-26-2014 08:05 PM
Error in TAR - tar: GNU features wanted on incompatible archive format. kuldeep.k Linux - General 3 08-14-2009 11:09 AM
tar this does not look like a tar archive exit depalyed from previous error tasay Linux - Software 1 07-01-2009 03:34 PM
Piping tar bzcat to add a file to a tar.bz2 archive DaveQB Linux - Software 0 06-02-2008 08:28 PM
Tar gives error when creating a tar file archive davidas Linux - Newbie 10 04-13-2004 12:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration