Gentoo Archives: gentoo-security

From: Marius Mauch <genone@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Re: Is anybody else worried about this?
Date: Mon, 08 Nov 2004 20:12:40
Message-Id: 20041108211214.3e5373e8@sven.genone.homeip.net
In Reply to: [gentoo-security] Re: Is anybody else worried about this? by Peter Simons
1 On 07 Nov 2004 19:51:17 +0100
2 Peter Simons <simons@××××.to> wrote:
3
4 > Marc Ballarin writes:
5 >
6 > > I explicitly said that signing should be implemented!
7 >
8 > Then what are we waiting for?
9
10 Ebuild signing is implemented already (it's not mandatory yet though),
11 signing of eclasses/profiles isn't done because of policy details (e.g.
12 do we need multiple sigs per eclass, would a single Manifest for all
13 eclasses be sufficient, ...)
14 But signature verification is a completely different beast.
15
16 Marius
17
18 --
19 Public Key at http://www.genone.de/info/gpg-key.pub
20
21 In the beginning, there was nothing. And God said, 'Let there be
22 Light.' And there was still nothing, but you could see a bit better.