[suse-security] Online Update Security


Suse's online update is using http or ftp to download patches
and updated packages from numerous mirrors.

What cryptographical checks are done to the downloaded packages
to ensure that they are what they pretend to be?

I belive that rpms buildin signatures are used?
Am I right, or are other precautions done by YOU?

Is there any documentation about that ?

best regards
Zoran Cvetkovic

