> as far as the package database was concerned, it was
"rpm -qV" is a command that will audit the signatures of a package's contents. I don't know if dpkg has something similar but it would be cool if it did.
"rpm -qV" is a command that will audit the signatures of a package's contents. I don't know if dpkg has something similar but it would be cool if it did.
But regardless of the signature algorithm, thanks for sharing the mechanism.
debsums is intended primarily as a way of determining what installed files have been locally modified by the administrator or damaged by media errors and is of limited use as a security tool.
Jammy comes out next month.
Though if you encounter an md5 second preimage attack that's pretty impressive.