You publish release.tar.gz and want users to be able to check its authenticity from a second, separate file, with the tarball itself left byte for byte unchanged. Which command produces that signature?
LPIC-1 Exam 102-500, objective 110. Security medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct gpg --detach-sign release.tar.gz
Correct. A detached signature is written to a separate file, release.tar.gz.sig, and contains nothing but the signature. The tarball is not rewritten, and users verify with gpg --verify release.tar.gz.sig release.tar.gz.
Not correct gpg --clearsign release.tar.gz
Wrong. --clearsign produces a new file in which the original content is embedded in readable form between armour headers. That suits plain text messages, not a binary archive.
Not correct gpg --sign release.tar.gz
Wrong. This creates release.tar.gz.gpg, a new file containing the compressed data together with the signature. Users would have to extract the payload back out of it rather than use the original archive.
Not correct gpg --encrypt --sign release.tar.gz
Wrong. That signs and also encrypts to a recipient, so only the holder of the matching private key could read the result. A public release must stay readable by everyone.
Why
The three signing modes differ only in what they do with the data: --sign packages the data and the signature into one file, --clearsign leaves the data readable inside that one file, and --detach-sign, short form -b, keeps the signature in a file of its own. Only the detached form leaves the original untouched, which is why distributions ship a .sig or .asc alongside each tarball. Verification of any of them needs the signer's public key already imported and validated in the checker's keyring.
Where this comes from
- Cited
- manual page gpg(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked