Gentoo Archives: gentoo-dev

From: Lance Albertson <ramereth@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Signing everything, for fun and for profit
Date: Sat, 20 May 2006 05:49:56
Message-Id: 446EACAA.7010608@gentoo.org
In Reply to: Re: [gentoo-dev] Re: Signing everything, for fun and for profit by Marius Mauch
1 Marius Mauch wrote:
2 > On Fri, 19 May 2006 12:28:04 -0400
3 > Peter <pete4abw@×××××××.net> wrote:
4 >
5 >> Who signs the Manifests? Why are some unsigned? Is there a single
6 >> Gentoo Security Key (like I know Slackware has and some other distros
7 >> to ensure the authenticity of their files)?
8 >
9 > Because the whole signing stuff isn't official, there has been a
10 > (partial) implementation plan a few years back, some people started to
11 > use it but is has never become official, the implementation is
12 > incomplete and there it can't and won't be enforced yet.
13
14 iirc, infra implemented signing of the daily portage snapshots. It was a
15 crude/simple way to get our tree 'signed', but its far from a scalable
16 nor proper solution. I think we only provided it since it didn't take
17 much effort for us to at least implement it and it gave the anal people
18 the ability to at least have some form of validity. It is one of the
19 options I know of currently.
20
21 Cheers-
22
23 --
24 Lance Albertson <ramereth@g.o>
25 Gentoo Infrastructure | Operations Manager
26
27 ---
28 GPG Public Key: <http://www.ramereth.net/lance.asc>
29 Key fingerprint: 0423 92F3 544A 1282 5AB1 4D07 416F A15D 27F4 B742
30
31 ramereth/irc.freenode.net

Attachments

File name MIME type
signature.asc application/pgp-signature