Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Verifying GNUPG Itself Before Using It To Verify Packages
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
archrax
n00b
n00b


Joined: 05 Dec 2011
Posts: 45

PostPosted: Thu Nov 28, 2013 1:27 pm    Post subject: Verifying GNUPG Itself Before Using It To Verify Packages Reply with quote

Hi guys,

I am a Linux newbie. I am currently attempting to install Gentoo in as secure a manner as possible.

I have downloaded a signed minimal installation iso and verified it on another machine.
I have a signed stage 3 tarball and verified it on another machine.

I have used the minimal install and successfully chrooted into my new environment. I have successfully manually copied across and unpacked the verified tarball rather than downloading an unverified one. I now want to use portage to do verified updates before proceeding further. But to do that I need to emerge gnupg. But how do I verify this gnupg package itself?

Is there a way of doing it using the gnupg from the installation rather than the chrooted environment? Or some other method? Otherwise it seems the Achilles heel is using an unverified package to verify all other packages.

Many thanks for your help.

EDIT: Ah, I think I already solved this problem. By using a validated Portage latest snapshot as opposed to using
Code:
# emerge-webrsync

as the manual suggests, GNUPG should be emerged from the validated snapshot now present on my system.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum