《包管理与摘要校验:dpkg/apt-file/apt-key/openssl/md5sum/sha1sum》

《包管理与摘要校验:dpkg/apt-file/apt-key/openssl/md5sum/sha1sum》

本文汇总 Debian 系包管理的高级操作(软件清单备份/恢复、命令归属查询、GPG key 处理),以及文件/字符串摘要校验(md5sum/sha1sum)与 openssl 加解密工具。

1 dpkg:本地包管理

dpkg 直接操作本地已安装的 deb 包(低于 apt)。

# 备份当前已安装软件清单(供迁移/恢复) sudo dpkg --get-selections > selections # 从清单批量恢复安装笔记 sudo dpkg --set-selections < selections sudo apt-get dselect-upgrade # 查询某软件是否已安装 dpkg -l | grep -i <software> # 彻底删除包(连同配置文件,删除依赖) apt-get remove --purge <package> # 用 dpkg 解包 .deb 里的文件到指定目录 dpkg -X xxx.deb /tmp/xxx

提示:卸载软件用 apt-get remove <pkg>,连带清理配置更推荐 --purge。

2 apt-file:命令归属包

想知道 /bin/ps 属于哪个包(Debian)时使用:

sudo apt-get install apt-file apt-file update apt-file search -F /bin/ps # -F 精确匹配 # procps: /bin/ps apt-file search -F /usr/bin/iostat # sysstat: /usr/bin/iostat # -x 使用正则 apt-file search -x "bin/ps$"

3 apt-key:添加 GPG 公钥

添加软件源签名公钥:

# 从 URL 下载并添加公钥 curl -s http://your.server/aptly.gpg.asc | sudo apt-key add - # 或从 keyserver 导入(如 Debian 报 NO_PUBKEY) sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys <KEY_ID>

报错 E: gnupg, gnupg2 and gnupg1 do not seem to be installed 时先安装: sudo apt-get update && sudo apt-get install -y gnupg2。

4 md5sum / sha1sum:摘要校验

# 文件校验 md5sum file.iso sha1sum file.iso # 字符串标识(-n 防止 echo 带入换行) echo -n "hello" | md5sum echo -n "secretKey=xxx&sid=2008" | sha1sum | awk '{print $1}' # 校验清单(生成 MD5SUMS 后批量校验) md5sum -c MD5SUMS

5 openssl:加解密与证书

5.1 AES 对称加解密

# 生成随机 key / iv(借用 md5 得到 32 字节 hex 字符串) key=$(openssl rand -base64 32 | md5sum | awk '{print $1}') iv=$(openssl rand -base64 32 | md5sum | awk '{print $1}') # 加密 echo "hello" | openssl enc -e -aes-256-cbc -a -K ${key} -iv ${iv} | xxd -p > secret.hex # 解密 cat secret.hex | xxd -r -p | openssl enc -d -aes-256-cbc -a -K ${key} -iv ${iv}

xxd 用于 hex ↔ 字符串互转:xxd -p(转 hex)、xxd -r -p(转回)。

5.2 查看证书

openssl x509 -in cert.pem -noout -text # 打印证书全部内容 openssl x509 -in cert.pem -noout -subject -nameopt oneline # 一行显示主体 openssl x509 -in cert.pem -noout -fingerprint # 输出指纹 openssl x509 -sha1 -in cert.pem -noout -fingerprint # SHA1 指纹 openssl x509 -in tmp.crt -out tmp.pem # crt → pem 格式转换 openssl req -in server.csr -noout -text # 查看 CSR 内容

6 总结

  • 备份/迁移软件清单:dpkg get/set-selections。
  • 找命令归属包:apt-file search。
  • 校验下载文件完整性:md5sum / sha1sum(关键文件建议 sha256sum)。
  • 需要加密传输小段数据/证书审阅时:openssl enc / openssl x509。
阅读 — · 全站 —
🎸 我的歌单 0 首