1to3
V2EX  ›  问与答

如何保证linux系统更新源的安全性?

  •  
  •   1to3 · Mar 22, 2013 · 3524 views
    This topic created in 4889 days ago, the information mentioned may be changed or developed.
    如果,163的源或者v2ex的源被入侵,或被管理员修改了某些包。使用这个源的系统,不都中招了吗?
    这种情况是如何避免的呢?
    6 replies    1970-01-01 08:00:00 +08:00
    swulling
        1
    swulling  
       Mar 22, 2013   ❤️ 1
    GPG验证,ubuntu/archlinux/debian都有的

    系统自带,不用操心
    swulling
        2
    swulling  
       Mar 22, 2013
    理论其实很简单,官方包都是用特定的私钥加密的,而对应的公钥是提前预装在你的系统内。

    所以Ubuntu要添加第三方源有一步是添加对应的公钥
    swulling
        3
    swulling  
       Mar 22, 2013
    加密 --> 签名
    1to3
        4
    1to3  
    OP
       Mar 22, 2013
    @swulling 就是保证了唯一性,跟那个网站的证书原理应该差不多吧。
    swulling
        5
    swulling  
       Mar 22, 2013
    @1to3 恩,大面上来说就是SSL的认证功能。当然原理是不同的,而且没有加密也没必要
    1to3
        6
    1to3  
    OP
       Mar 22, 2013
    @swulling 迅雷离线,好像没有此类安全机制。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   2900 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 23ms · UTC 14:36 · PVG 22:36 · LAX 07:36 · JFK 10:36
    ♥ Do have faith in what you're doing.