Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Tree-signing GLEPS review notes
Date: Sun, 31 Jan 2010 10:12:21
Message-Id: robbat2-20100131T100444-075623426Z@orbis-terrarum.net
In Reply to: [gentoo-dev] Tree-signing GLEPs update by "Robin H. Johnson"
1 The GLEP numbering represents the order in which I wrote the GLEPs. It
2 originally started off as just two very large GLEPs. The informational
3 GLEP and the changes GLEP. I split it out BECAUSE I realized that many
4 of the parts should stand on their own merits.
5
6 For anybody looking for a hand in reviewing these, I suggest tackling
7 them in the following order:
8
9 Phase 0, background:
10 --------------------
11 GLEP57 - Security overview
12
13 Phase 1, isolated improvements to Manifest2:
14 --------------------------------------------
15 GLEP59 - Manifest2 hashes
16 GLEP61 - Manifest2 compression
17
18 Phase 2, adding to Manifest2 infrastructure:
19 --------------------------------------------
20 GLEP60 - Manifest2 filetypes
21
22 Phase 3, Infra->User security:
23 ------------------------------
24 GLEP58 - MetaManifest
25
26 Phase 4, Dev->infra security:
27 -----------------------------
28 I still need to write the following:
29 GLEPxx - Developer Process Security
30 GLEPxx - GnuPG Policies and Handling
31
32 --
33 Robin Hugh Johnson
34 Gentoo Linux: Developer, Trustee & Infrastructure Lead
35 E-Mail : robbat2@g.o
36 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85