devsetup1-1 Exercise 2: Practising Checksum Verification ========================================================= STEPS ----- cd ~ echo "hello devserver" > testfile.txt sha512sum testfile.txt > testfile.txt.sha512 sha512sum -c testfile.txt.sha512 Expected output of the last command: testfile.txt: OK Now change one character: echo "hello devserveR" > testfile.txt sha512sum -c testfile.txt.sha512 Expected output: testfile.txt: FAILED sha512sum: WARNING: 1 computed checksum did NOT match WHAT EACH RESULT PROVES ----------------------- "OK" means the file's contents are byte-for-byte the same as when the checksum was made. "FAILED" means at least one byte is different. It does not say what changed or why. A corrupted download and a deliberately altered file give the same result. WHAT gpg --verify ADDS ---------------------- A checksum only proves the file matches the checksum file. If an attacker replaced BOTH the ISO and the SHA512SUMS file, the check would still say OK. Debian signs the SHA512SUMS file. Running gpg --verify SHA512SUMS.sign SHA512SUMS checks that signature against Debian's published signing key, so it proves the checksum file itself really came from Debian and has not been tampered with. The chain is: signature -> checksum file -> ISO. To rely on it you must also check that the key fingerprint gpg reports matches the fingerprints published on Debian's verification page (debian.org/CD/verify); otherwise you have only proved the file was signed by somebody. WHY THIS WORKS AS AN ANSWER --------------------------- It separates the two questions that verification answers: "did I receive the file intact?" (checksum) and "is this the file the publisher meant me to have?" (signature). Doing the first on a throwaway file makes the behaviour visible without needing a 700 MB download.