PDA

View Full Version : PLF repository verification question?


wargames
November 19th, 2005, 02:06 AM
Hi, I was using this PLF guide (http://wiki.ubuntu-fr.org/doc/plf) posted in the forums to install libdvdcss2 and w32codecs.
I used the Secondary mirrors provided in my sources.list:

## FTP mirror from http://free.fr (french ISP)
deb ftp://ftp.free.fr/pub/Distributions_Linux/plf/ubuntu/plf/ breezy free non-free
deb-src ftp://ftp.free.fr/pub/Distributions_Linux/plf/ubuntu/plf/ breezy free non-free

And after I did a "sudo apt-get update" and then issued a "sudo apt-get install libdvdcss2" and then a "sudo apt-get install w32codecs" both times it asked me the following:

WARNING: The following packages cannot be authenticated!

Install these packages without verification [y/N]?

I went ahead and answered "yes" both times, but I'm now wondering if it was safe to do so?

Was it alright to go ahead and answer "yes" and install both of these packages anyway from these secondary PLF repositories? Anyone else get this warning?

uberlinux
November 19th, 2005, 04:15 AM
I would definately trust the PLF site & repositories.

manicka
November 19th, 2005, 05:01 AM
I would definately trust the PLF site & repositories.
Absolutely, I would trust them. They have been well known and trusted packagers for Mandrake/Mandriva for a number of years and have recently started an Ubuntu repo.

wargames
November 19th, 2005, 10:58 PM
Thanks guys. :)

rattusdatorum
December 13th, 2005, 04:21 PM
and why is there the auth problem anyway?

manicka
December 14th, 2005, 04:22 AM
and why is there the auth problem anyway?

because the repo is not an official ubuntu one

nocturn
December 14th, 2005, 04:32 AM
I would definately trust the PLF site & repositories.

The point is not if you trust PLF, which I would also do. But packages that are not signed by a trusted key may be tampered with.

A cracker could have uploaded a backdoored version of the w32codecs package without the knowledge of PLF, this thread would be addressed by signing and authenticating the packages.

I'm not warning anyone not to install them, but keep in mind that this is a possibility.

nocturn
December 14th, 2005, 04:33 AM
because the repo is not an official ubuntu one

Yes, but unofficial Repos can also sign packages, you would only have to import their key once.

uopjohnson
February 10th, 2006, 01:44 AM
Does anyone know where to find the public key for the plf repo?

Freyr Vanir
February 12th, 2006, 01:19 AM
Here is the PLF Public Key.
http://plf.zarb.org/plf.asc

You can find a link to it on this webpage too.
http://plf.zarb.org/packages.php