Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Cc: zmedico@g.o
Subject: Re: [gentoo-dev] RFC: Gentoo GPG key policies
Date: Fri, 15 Mar 2013 01:01:31
Message-Id: robbat2-20130315T005848-062500060Z@orbis-terrarum.net
In Reply to: Re: [gentoo-dev] RFC: Gentoo GPG key policies by "Michał Górny"
1 On Thu, Mar 14, 2013 at 05:14:15PM +0100, Michał Górny wrote:
2 > If that means doing an additional signature every time something is
3 > going to be committed, that sounds like an overkill. If we were to do
4 > something radical, I'd rather be in favor of disabling keyword
5 > expansion completely and finally being able to do sane commits.
6 I foresee it as more of:
7 IFF this commit will call GPG later, ensure the agent can access the
8 secret key BEFORE trying to sign at the end.
9
10 As to how to accomplish this, it's either a throwaway sig, or poking the
11 agent protocol directly.
12
13 --
14 Robin Hugh Johnson
15 Gentoo Linux: Developer, Trustee & Infrastructure Lead
16 E-Mail : robbat2@g.o
17 GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85

Replies

Subject Author
Re: [gentoo-dev] RFC: Gentoo GPG key policies Michael Mol <mikemol@×××××.com>