Gentoo Archives: gentoo-dev

From: Michael Weber <xmw@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: [gentoo-dev-announce] please sign your manifests
Date: Wed, 13 Feb 2013 20:30:25
Message-Id: 511BF7CA.1090106@gentoo.org
In Reply to: [gentoo-dev] Re: [gentoo-dev-announce] please sign your manifests by Agostino Sarubbo
1 On 02/13/2013 09:07 PM, Agostino Sarubbo wrote:
2 > As most of us do, I do the commit from another machine, not mine. So, for ssh
3 > I'm using ssh -A to forward the key and I'm interested to find a way to do it
4 > for the gpg key.
5 >
6 > I found an how-to that uses socat ( http://superuser.com/questions/161973/how-
7 > can-i-forward-a-gpg-key-via-ssh-agent ) but does not work as expected.
8
9 GPG agents do not transport keys, just passphrases.
10
11 I once used a patch against openssh to enable forwarding of domain
12 sockets, it applies to current 6.1_p1.
13
14 http://www.25thandclement.com/~william/projects/streamlocal.html
15
16 Maybe we should add this to our openssh version, I'd appreciate it.
17
18 > This is an example: http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-
19 > x86/app-portage/splat/Manifest?revision=1.45&view=markup
20 >
21 > The manifest apparently is signed, but there is no really gpg sign.
22
23 look closely to the output of repoman commit, there is a small "gpg
24 failed" or somethink like that.
25
26
27 --
28 Michael Weber
29 Gentoo Developer
30 web: https://xmw.de/
31 mailto: Michael Weber <xmw@g.o>

Replies