1 |
While I'm absolutely in favour of the overall intent here, I'm not so |
2 |
sure of the design. |
3 |
|
4 |
I'm worried about the proliferation of tiny packages just to convey the |
5 |
keys; and how versioning should work if upstream rotates their keys. |
6 |
I picked this message in the thread to respond to, because it was |
7 |
clearest that this could break when the keys are rotated. The old |
8 |
releases might not be verifiable with the new keys. |
9 |
|
10 |
Additionally: |
11 |
- not all upstream providers ship .asc files of their keys |
12 |
- some upstreams use signed DIGESTS files rather than directly signing |
13 |
the distfiles (esp. where distfiles are larger) |
14 |
|
15 |
Can we instead: |
16 |
Inside the ebuild and/or metadata.xml: convey: |
17 |
1. URL(s) to fetch keys, incl a keyserver support |
18 |
2. Full key fingerprint |
19 |
|
20 |
-- |
21 |
Robin Hugh Johnson |
22 |
Gentoo Linux: Dev, Infra Lead, Foundation Treasurer |
23 |
E-Mail : robbat2@g.o |
24 |
GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85 |
25 |
GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136 |