Gentoo Archives: gentoo-dev

From: Kent Fredric <kentfredric@×××××.com>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: Verification of installed packages (was Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests))
Date: Fri, 17 Jul 2015 10:43:41
Message-Id: CAATnKFDtVT3e6x7qenkpMP9o3ijAs6TpuqmA7wxz5sTuyChymA@mail.gmail.com
In Reply to: Verification of installed packages (was Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests)) by Andrew Savchenko
1 On 17 July 2015 at 22:34, Andrew Savchenko <bircoph@g.o> wrote:
2 > 2. Add an optional feature to emerge (or even to PMS?) allowing user
3 > to provide a usable GPG key for signing packages CONTENTS files
4 > after its generation. In order for such key to be usable during
5 > emerge run, gpg-agent should be used; alternatively it may be
6 > allowed to sign already installed packages on a trusted system.
7 > 3. Of course backward compatibility with old CONTENTS format should
8 > be kept.
9
10
11 To keep things simple, I'd suggest storing the signature externally to
12 the CONTENTS file.
13
14 This would be more convenient for any tools that are trying to scrape
15 the CONTENTS files with regex/grep not needing to first unwrap them. (
16 Not to mention trivial to determine which packages have signatures
17 without needing to actually read the files )
18
19 Though, seeing we're going down this road, you could sign the whole vdb dir.
20
21 --
22 Kent
23
24 KENTNL - https://metacpan.org/author/KENTNL