LWN.net Logo

Fedora and secure release upgrades

Fedora and secure release upgrades

Posted Dec 20, 2012 15:34 UTC (Thu) by n8willis (editor, #43041)
In reply to: Fedora and secure release upgrades by etienne
Parent article: Fedora and secure release upgrades

But the issue that you cannot *know* whether or not your F17 system is compromised by checking it with F17 itself. That's the trust chain problem. To be sure you could trust the alleged F17 key, you would have had to have already downloaded a key asserting to be F16-signed. But to verify that, you would have to have downloaded a key asserting to be F15-signed, and you would have to have an F14-signed key for that, so on. Even if that chain-of-trust would work in theory, all the way back to the bootstrapping of the project, reality is that those older signed-key-packages don't exist (and never will).

Nate


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds