1 |
Patrick Lauer wrote: |
2 |
|
3 |
> Signing strategies |
4 |
> ================== |
5 |
> |
6 |
> Once there is an agreement on what files to sign with what kind of keys |
7 |
> there remains the question how to sign it. There are at least three |
8 |
> strategies: |
9 |
> [...] |
10 |
|
11 |
I prefer a semi-secure solution appearing soon rather than waiting |
12 |
another three+ years for a potentially better solution. |
13 |
|
14 |
Currently users only have two choices : |
15 |
|
16 |
- masterkey-signed portage snapshots |
17 |
- unsigned (and so, insecure) rsync mirrors |
18 |
|
19 |
This is obviously not satisfying. |
20 |
|
21 |
It has taken years to try to get per-developer signing implemented, |
22 |
without success. We should try to do masterkey signing ("simple" method) |
23 |
and see if we go somewhere. It's is so much better than nothing. |
24 |
|
25 |
So I would rather work on ensuring everything in portage gets properly |
26 |
signed rather than designing key policies, cross-signing strategies and |
27 |
ways to force developers to sign properly. Given the current state of |
28 |
Gentoo it is a much more reachable goal. |
29 |
|
30 |
-- |
31 |
Thierry Carrez (Koon) |
32 |
Gentoo Security Team and Gentoo Council Member |
33 |
-- |
34 |
gentoo-dev@g.o mailing list |