1 |
On Wed, 2004-03-24 at 16:07, Chris Bainbridge wrote: |
2 |
> c) for each signature in .secure/*.asc check whether its in the ACL list, |
3 |
> then call `gpg --verify .secure/sig.asc .secure/hash` to verify it. We can |
4 |
> set auto-key-retrieve in case we don't already have the key. |
5 |
|
6 |
Something that I've been trying to figure out in this whole discussion |
7 |
of rapidly expiring keys is what happens to machines that don't have |
8 |
at-will access to the public internet: |
9 |
|
10 |
... a disconnected machine (like a laptop) who is away from the internet |
11 |
for days or weeks at a time, or |
12 |
|
13 |
... a server node that doesn't get its packages from the net at all, but |
14 |
rather is part of a production farm which gets its updates from some |
15 |
local local mirror/build machine only when the site administrators make |
16 |
a new local set of packages available to that server farm. |
17 |
|
18 |
What happens in those scenarios? |
19 |
|
20 |
AfC |
21 |
Toronto |
22 |
|
23 |
-- |
24 |
Andrew Frederick Cowie |
25 |
Operational Dynamics Consulting Pty Ltd |
26 |
|
27 |
Australia +61 2 9977 6866 North America +1 646 472 5054 |
28 |
|
29 |
http://www.operationaldynamics.com/ |
30 |
|
31 |
-- |
32 |
gentoo-dev@g.o mailing list |