Am Fr, den 01.10.2004 schrieb TongKe Xue um 1:18:
- What is RedHat's GPG key? Up2date said it was going to "install the
key" but didn't say what the key was.
http://www.fedorafaq.org/#gpgsig
- How can I ensure that the packages I download are from
RedHat/Fedora and not spoofed/trojaned? (By the man in middle attack)
This is the intend of the GPG signing and md5sum. You can run
rpm -Kv packagename-version.arch.rpm
and check the output.
rpm or the "frontends" up2date or yum handle the signature and checksum checking automatically.
--TongKe
Alexander