Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [enhancement proposal] Per-file Manifest GPG signatures
Date: Thu, 07 Oct 2010 20:09:14
Message-Id: robbat2-20101007T200504-179323562Z@orbis-terrarum.net
In Reply to: Re: [gentoo-dev] [enhancement proposal] Per-file Manifest GPG signatures by James Cloos
1 On Thu, Oct 07, 2010 at 10:17:01AM -0400, James Cloos wrote:
2 > >>>>> "RHJ" == Robin H Johnson <robbat2@g.o> writes:
3 > >> Include the signing keyid in the filename to support both allowing
4 > >> multiple devs to sign a file and an easy indication of who signed it.
5 > RHJ> You can extract keyid from any signature trivially.
6 > But if it is not in the filename you cannot have multiple sig files.
7 This does still bloat the inode count. The variant was to have multiple
8 signed blocks inside the Manifest file.
9
10 > >> Don't stop everything just because /one/ package has a problem.
11 > RHJ> This is already controllable.
12 > If you mean --keep-going, that may work sometimes, but never did when I
13 > really needed it.
14 "FEATURES=-severe" iirc, but I do agree that more control over signature
15 validation in FEATURES would be beneficial.
16
17 --
18 Robin Hugh Johnson
19 Gentoo Linux: Developer, Trustee & Infrastructure Lead
20 E-Mail : robbat2@g.o
21 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85