Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] GLEP59 - Manifest2 hashes
Date: Sun, 31 Jan 2010 09:57:35
Message-Id: robbat2-20100131T094902-902405888Z@orbis-terrarum.net
In Reply to: [gentoo-dev] Tree-signing GLEPs update by "Robin H. Johnson"
Changes:
- This GLEP should be considered regardless of GLEP58 passes, as it has
  independent value.
- Python 2.5 is widely deployed now (and a dep on newer versions of
  Portage), so SHA512 is easily available.
- RIPEMD160 was broken, so drop it as well.
- Add WHIRLPOOL algorithm as it's not vulnerable to the same
  decomposition analysis introduced by Wang et al.
- Add more detail to the migration plan.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : robbat2@g.o
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

Attachments

File name MIME type
glep-0059.txt text/plain

Replies

Subject Author
Re: [gentoo-dev] GLEP59 - Manifest2 hashes "Robin H. Johnson" <robbat2@g.o>
Re: [gentoo-dev] GLEP59 - Manifest2 hashes Doug Goldstein <cardoe@g.o>