Linux workstation

Debian 12 (Bookworm) native package

debsig-verify

Debian package signature verification tool

Packages / Debian 12 (Bookworm) / admin / debsig-verify

[Source: debsig-verify]

Package: debsig-verify (0.28+b4)

Maintainers:

Dpkg Developers

Debian package signature verification tool

Other Packages Related to debsig-verify:

  • dep: [libc6] (>= 2.34)

    GNU C Library: Shared libraries

  • dep: [libexpat1] (>= 2.0.1)

    XML parsing C library - runtime library

  • dep: [libmd0] (>= 0.0.0)

    message digest functions from BSD systems - shared library

  • dep: [gpg]

    GNU Privacy Guard -- minimalist public key operations

  • dep: [gnupg]

    GNU privacy guard - a free PGP replacement

  • sug: [debian-keyring]

    GnuPG keys of Debian Developers and Maintainers

  • sug: [debsigs]

    toolset for cryptographically signing Debian packages

  • enh: [dpkg]

    Debian package management system

Download debsig-verify

ArchitecturePackage SizeInstalled SizeFiles
amd6436 KiB100 KiB[list of files]
arm6435 KiB104 KiB[list of files]

Percorsi file del pacchetto (10)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /usr/bin/debsig-verify
  • /usr/share/doc/debsig-verify/changelog.gz
  • /usr/share/doc/debsig-verify/copyright
  • /usr/share/doc/debsig-verify/examples/generic.pol
  • /usr/share/doc/debsig-verify/examples/keyid.pol
  • /usr/share/doc/debsig-verify/examples/nameid.pol
  • /usr/share/doc/debsig-verify/policy.dtd
  • /usr/share/doc/debsig-verify/policy-syntax.txt
  • /usr/share/lintian/overrides/debsig-verify
  • /usr/share/man/man1/debsig-verify.1.gz

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Usa questo pacchetto

OpenFactory può avviare questo sistema operativo in una macchina virtuale del browser, o iniziare una costruzione che include il nome nativo del pacchetto di questo record.

Versioni, suite e repository

Ogni riga è metadato dell'indice pacchetti per una versione, architettura, suite e repository. Nomi, URL e dimensioni arrivano dalla fonte; un link è un punto di recupero mutabile, non una redistribuzione OpenFactory.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
0.28+b4bookworm / mainamd64Debian 12 · main · amd6436 KiB100 KiBpool/main/d/debsig-verify/debsig-verify_0.28+b4_amd64.deb
0.28+b4bookworm / mainarm64Debian 12 · main · arm6435 KiB104 KiBpool/main/d/debsig-verify/debsig-verify_0.28+b4_arm64.deb

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Checksum e date di osservazione

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

0.28+b4 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 2e22f14551bcde008fd69ec0adf8284f26b2b047cfc305a4dcd060c1bac14791

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '2e22f14551bcde008fd69ec0adf8284f26b2b047cfc305a4dcd060c1bac14791' 'debsig-verify_0.28+b4_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

0.28+b4 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 8c35640beb6e0094e144f89782fdaeee1b65920efae8c24e192df4fae6b72c8e

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '8c35640beb6e0094e144f89782fdaeee1b65920efae8c24e192df4fae6b72c8e' 'debsig-verify_0.28+b4_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

Completezza del record

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
0/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 90/100

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5, Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

Fonti e provenienza

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Observed SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Observed SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Result: match verified

debsig-verify Package for Debian 12 (Bookworm) | OpenFactory