1 |
> <pedant>OpenPGP (GPG is just one implementation)</pedant>, but indeed, |
2 |
> that is what the gentoo-keys project is about. There is experimental |
3 |
> support for OpenPGP verification in portage already using gkeys. |
4 |
> Currently the focus is on getting developer's keys up to GLEP63 specs, |
5 |
> i currently see 36 good Gentoo developer keys. The scheme is also |
6 |
> flexible enough to allow for overlays. |
7 |
> |
8 |
> |
9 |
> https is not a good protection against MITM when factoring in global |
10 |
> PKIX CA setup, nor would it protect with regards to server compromise. |
11 |
> So the only viable way to secure ebuild repositories is proper OpenPGP |
12 |
> usage. |
13 |
|
14 |
I'd double that pedant paranoid! :) |
15 |
|
16 |
-- |
17 |
Best regards, |
18 |
mva |