Gentoo Archives: gentoo-dev

From: Andrew Cowie <andrew@×××××××××××××××××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] 2004.1 will not include a secure portage.
Date: Sat, 27 Mar 2004 03:37:55
Message-Id: 1080358098.5730.43.camel@localhost
In Reply to: Re: [gentoo-dev] 2004.1 will not include a secure portage. by Chris Bainbridge
1 On Wed, 2004-03-24 at 16:07, Chris Bainbridge wrote:
2 > c) for each signature in .secure/*.asc check whether its in the ACL list,
3 > then call `gpg --verify .secure/sig.asc .secure/hash` to verify it. We can
4 > set auto-key-retrieve in case we don't already have the key.
5
6 Something that I've been trying to figure out in this whole discussion
7 of rapidly expiring keys is what happens to machines that don't have
8 at-will access to the public internet:
9
10 ... a disconnected machine (like a laptop) who is away from the internet
11 for days or weeks at a time, or
12
13 ... a server node that doesn't get its packages from the net at all, but
14 rather is part of a production farm which gets its updates from some
15 local local mirror/build machine only when the site administrators make
16 a new local set of packages available to that server farm.
17
18 What happens in those scenarios?
19
20 AfC
21 Toronto
22
23 --
24 Andrew Frederick Cowie
25 Operational Dynamics Consulting Pty Ltd
26
27 Australia +61 2 9977 6866 North America +1 646 472 5054
28
29 http://www.operationaldynamics.com/
30
31 --
32 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] 2004.1 will not include a secure portage. Paul de Vrieze <pauldv@g.o>