diff options
-rw-r--r-- | pcr/samhain/PKGBUILD | 10 | ||||
-rw-r--r-- | pcr/samhain/PKGBUILD.sig | bin | 543 -> 543 bytes |
2 files changed, 5 insertions, 5 deletions
diff --git a/pcr/samhain/PKGBUILD b/pcr/samhain/PKGBUILD index 5bfb5082a..4070f0ef2 100644 --- a/pcr/samhain/PKGBUILD +++ b/pcr/samhain/PKGBUILD @@ -2,7 +2,7 @@ # Contributor: Brad Arrington pkgname=samhain -pkgver=4.1.0 +pkgver=4.1.2 pkgrel=1 pkgdesc="file integrity / intrusion detection system" arch=(i686 x86_64) @@ -14,9 +14,9 @@ source=("http://www.la-samhna.de/samhain/${pkgname}-current.tar.gz" 'PKGBUILD') validpgpkeys=('CB6E213A349B8DF9E96B622AC3F4FFCF3EAE8697' # PKGBUILD Maintainer's key 'EF6CEF54701A0AFDB86AF4C31AAD26C80F571F6C') # Rainer Wichmann -sha512sums=('ec43208be7254f9d7296fac22e1de96bb29b6effad452eb1d38bbd36661c47a8f58564c596909140f37540c3158be24e4e24fcb27590addd11e533736a7a9720' -'SKIP' -'SKIP') +sha512sums=('0dcb89b7a11b0aaef7b306360857c64b505651b526f7c3030ac7186f1c334c745df7b544e16fa9edac260156b1fa32d44e2276cf2476807d0ea0c011d05c9e4f' + 'SKIP' + 'SKIP') pkgver() { tar -ztvf samhain-current.tar.gz | head -n1 | awk '{print $6}' | sed "s/samhain-//" | sed "s/.tar.gz//" # get latest version number @@ -25,7 +25,7 @@ tar -ztvf samhain-current.tar.gz | head -n1 | awk '{print $6}' | sed "s/samhain- build() { gpg --verify PKGBUILD.sig PKGBUILD echo "Note: If the GPG verification fails, import the PKGBUILD maintainer's GPG key. See: https://wiki.parabola.nu/GnuPG#Import_key" - whirlpoolsum=('1a017bd7d47f638d0c2e67a08ceda626c69037d870ba5401c832a859959bd604b35679d7aa6c510255dcd00c64eed52dbf9f39c386f45f320e2a2561f5c17983') + whirlpoolsum=('09be99572c31d76dc58ccb5963e615ea87faf689858cd4372883df5905d1fff792807641adb85c9719269577ae81e679936d0488a27cdb055724c6ed6eaa3d5b') [[ "$(openssl dgst -r -whirlpool samhain-current.tar.gz | awk '{print $1}')" = ${whirlpoolsum} ]] && echo "Whirlpool checksum passed." || { echo "Whirlpool checksum failed!!" ; exit 1; } # This is an added security layer. If SHA512 for some unlikely reason fails, whirlpool will check and abort if it too fails to match. gpg --verify samhain-${pkgver}.tar.gz.asc samhain-${pkgver}.tar.gz echo "Note: If the GPG verification fails, import the Samhain GPG key: http://www.la-samhna.de/samhain/s_rkey.html" diff --git a/pcr/samhain/PKGBUILD.sig b/pcr/samhain/PKGBUILD.sig Binary files differindex b1ceb34e9..3260aef8e 100644 --- a/pcr/samhain/PKGBUILD.sig +++ b/pcr/samhain/PKGBUILD.sig |