Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Signing everything, for fun and for profit
Date: Sat, 20 May 2006 23:56:08
Message-Id: 20060520234851.GC19246@curie-int.vc.shawcable.net
In Reply to: [gentoo-dev] Re: Signing everything, for fun and for profit by Peter
1 On Sat, May 20, 2006 at 06:54:44AM -0400, Peter wrote:
2 > On Thu, 18 May 2006 23:45:17 +0200, Patrick Lauer wrote:
3 >
4 > >The problem, in short, is how to handle the checksumming and signing of
5 > >gentoo-provided files so that manipulation by external entities becomes
6 > >difficult.
7 > all snip...
8 >
9 > PMFJI, but as a user, not a security expert, I had a few thoughts that I'd
10 > like to throw in. Thanks to Patrick, he helped me to drill down some of
11 > the ideas and I present them for consideration. It's just a framework, so
12 > I will be brief.
13 Even larger snip.
14
15 I was actually looking at something similar to this, for the 'simple'
16 portion of Patrick's plan. You have most of the major ideas down, but
17 missed a few holes, and sticking points.
18
19 I'll try to get a writeup of it out later tonight, got a double-date
20 first ;-).
21
22 Thanks for the good writeup of Slackware as well, it's one I didn't
23 elaborate much on when I previously described the processes of
24 RPM-distros and Debian.
25
26 --
27 Robin Hugh Johnson
28 E-Mail : robbat2@g.o
29 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85