1 |
Dnia 2015-05-16, o godz. 23:48:01 |
2 |
Alon Bar-Lev <alonbl@g.o> napisał(a): |
3 |
|
4 |
> On 15 May 2015 at 17:51, Michał Górny <mgorny@g.o> wrote: |
5 |
> > Please note that the current syncing code does not verify the OpenPGP |
6 |
> > signature to confirm the authenticity of fetched snapshots and deltas. |
7 |
> > This feature will be added as soon as gentoo-keys support in Portage is |
8 |
> > available. |
9 |
> |
10 |
> These are great news! |
11 |
> We can retire the webrsync. |
12 |
> Why not sign it similar to the portage snapshot are signed for now? |
13 |
> The webrsync signature validation is quite simple. |
14 |
|
15 |
All signing is in place already for a long time. Just the verification |
16 |
code is missing, and it wasn't added because I was told to wait for |
17 |
gentoo-keys. |
18 |
|
19 |
> Just a reminder: please note the rollback prevention mechanism in |
20 |
> webrsync, it is not enough to check signature, but also prevent older |
21 |
> snapshot to be used. |
22 |
|
23 |
Truth be told, the squashdelta syncing wasn't really made with rollback |
24 |
prevention in mind. I can't think immediately of any solution that |
25 |
would prevent accidental rollback while preserving the intended |
26 |
flexibility. |
27 |
|
28 |
-- |
29 |
Best regards, |
30 |
Michał Górny |