《包管理与摘要校验:dpkg/apt-file/apt-key/openssl/md5sum/sha1sum》
本文汇总 Debian 系包管理的高级操作(软件清单备份/恢复、命令归属查询、GPG key 处理),以及文件/字符串摘要校验(md5sum/sha1sum)与 openssl 加解密工具。
1 dpkg:本地包管理
dpkg 直接操作本地已安装的 deb 包(低于 apt)。
# 备份当前已安装软件清单(供迁移/恢复)
sudo dpkg --get-selections > selections
# 从清单批量恢复安装笔记
sudo dpkg --set-selections < selections
sudo apt-get dselect-upgrade
# 查询某软件是否已安装
dpkg -l | grep -i <software>
# 彻底删除包(连同配置文件,删除依赖)
apt-get remove --purge <package>
# 用 dpkg 解包 .deb 里的文件到指定目录
dpkg -X xxx.deb /tmp/xxx
提示:卸载软件用
apt-get remove <pkg>,连带清理配置更推荐--purge。
2 apt-file:命令归属包
想知道 /bin/ps 属于哪个包(Debian)时使用:
sudo apt-get install apt-file
apt-file update
apt-file search -F /bin/ps # -F 精确匹配
# procps: /bin/ps
apt-file search -F /usr/bin/iostat
# sysstat: /usr/bin/iostat
# -x 使用正则
apt-file search -x "bin/ps$"
3 apt-key:添加 GPG 公钥
添加软件源签名公钥:
# 从 URL 下载并添加公钥
curl -s http://your.server/aptly.gpg.asc | sudo apt-key add -
# 或从 keyserver 导入(如 Debian 报 NO_PUBKEY)
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys <KEY_ID>
报错
E: gnupg, gnupg2 and gnupg1 do not seem to be installed时先安装:sudo apt-get update && sudo apt-get install -y gnupg2。
4 md5sum / sha1sum:摘要校验
# 文件校验
md5sum file.iso
sha1sum file.iso
# 字符串标识(-n 防止 echo 带入换行)
echo -n "hello" | md5sum
echo -n "secretKey=xxx&sid=2008" | sha1sum | awk '{print $1}'
# 校验清单(生成 MD5SUMS 后批量校验)
md5sum -c MD5SUMS
5 openssl:加解密与证书
5.1 AES 对称加解密
# 生成随机 key / iv(借用 md5 得到 32 字节 hex 字符串)
key=$(openssl rand -base64 32 | md5sum | awk '{print $1}')
iv=$(openssl rand -base64 32 | md5sum | awk '{print $1}')
# 加密
echo "hello" | openssl enc -e -aes-256-cbc -a -K ${key} -iv ${iv} | xxd -p > secret.hex
# 解密
cat secret.hex | xxd -r -p | openssl enc -d -aes-256-cbc -a -K ${key} -iv ${iv}
xxd 用于 hex ↔ 字符串互转:
xxd -p(转 hex)、xxd -r -p(转回)。
5.2 查看证书
openssl x509 -in cert.pem -noout -text # 打印证书全部内容
openssl x509 -in cert.pem -noout -subject -nameopt oneline # 一行显示主体
openssl x509 -in cert.pem -noout -fingerprint # 输出指纹
openssl x509 -sha1 -in cert.pem -noout -fingerprint # SHA1 指纹
openssl x509 -in tmp.crt -out tmp.pem # crt → pem 格式转换
openssl req -in server.csr -noout -text # 查看 CSR 内容
6 总结
- 备份/迁移软件清单:dpkg get/set-selections。
- 找命令归属包:apt-file search。
- 校验下载文件完整性:md5sum / sha1sum(关键文件建议 sha256sum)。
- 需要加密传输小段数据/证书审阅时:openssl enc / openssl x509。
阅读 —
·
全站 —