LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-13-2007, 12:58 AM   #1
a49002
LQ Newbie
 
Registered: Feb 2007
Posts: 5

Rep: Reputation: 0
How to Verify Software before installation?


Folks,

I am new to Linux and wondering what the process is to verify software packages before installation. Specifically, I want to install GnuCash 2.0.5 into Ubuntu. The Sourceforge website has the GnuCash download links plus a .sig file. When I try and verify the .sig file against the downloaded gnucash.gz file I get a warning that there is no public Key?

Unfortunately, there are no MD5 sums shown at the website so what is the usual process for checking software? Do I have to firstly import a Key for GnuCash from a Key server?

I appreciate any help or direction.

Paul
 
Old 03-13-2007, 02:59 AM   #2
Simon Bridge
LQ Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211

Rep: Reputation: 198Reputation: 198
What is wrong with:

sudo apt-get install gnucash

(To verify a file, you must download the public key as well. Available from the same website.)
 
Old 03-13-2007, 03:40 AM   #3
a49002
LQ Newbie
 
Registered: Feb 2007
Posts: 5

Original Poster
Rep: Reputation: 0
Why I want to verify the Download

Quote:
Originally Posted by Simon Bridge
What is wrong with:

sudo apt-get install gnucash

(To verify a file, you must download the public key as well. Available from the same website.)
Thanks for the reply. There has to be a reason Websites include a .sig file for verification (as is the case often with MD5) and with a piece of software that holds all ones personal finance records it makes sense to me to verify that the file is untampered with, especially if downloading from a mirror. I will look for the public key. Thanks.

Paul
 
Old 03-13-2007, 08:01 AM   #4
pixellany
LQ Veteran
 
Registered: Nov 2005
Location: Annapolis, MD
Distribution: Mint
Posts: 17,809

Rep: Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743
If someone is going to tamper with an application file and post it to a mirror, then they can also tamper with the public key.

Assuming your data is backed up, then the risk of simply installing does not seem terribly high.

BUT--why not get Gnucash from the Ubuntu repository????
 
Old 03-13-2007, 08:14 PM   #5
Simon Bridge
LQ Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211

Rep: Reputation: 198Reputation: 198
Quote:
When I try and verify the .sig file against the downloaded gnucash.gz file I get a warning that there is no public Key?
The error message means you need to get the public key.

Presumably there is also a reason sites include checksums and ask you verify the package against them. You were the one asking how to verify packages. Perhaps you need to be more specific about what it is about the package you want to verify?

Note: tampering with software is a fundamental right in OSS/FS. Asking for untampered-with software would seem to defeat the purpose. So I imagine you are concerned about malicious tampering?

If a distributer is concerned about things of this nature, they will usually sign the web page (ssh certificates and things of such ilk). Things you get from that web page would then come from them (with high assurance, i.e. over an ssh tunnel.) and is unlikely to be tampered with en-route.

Last edited by Simon Bridge; 03-13-2007 at 08:17 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I verify my burnt installation DVD? noob_nz SUSE / openSUSE 6 02-16-2006 07:29 PM
Installation Software for Custom Developed Java/Perl Software donkey123 Linux - Software 0 06-15-2005 05:26 PM
verify before continue - how to? babag Programming 8 05-05-2005 05:28 AM
Verify a CD-ROM VorlonInfoTech Linux - Hardware 1 03-07-2005 02:37 AM
verify faulty software raid hard drive jwstric2 Linux - Hardware 0 07-06-2004 10:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration