Gentoo Archives: gentoo-portage-dev

From: Zac Medico <zmedico@g.o>
To: gentoo-portage-dev@l.g.o
Subject: Re: [gentoo-portage-dev] [PATCH] emerge-webrsync: use gkeys to verify gpg signatures (bug 597918)
Date: Thu, 27 Oct 2016 19:34:04
Message-Id: 1bdf4651-0152-0eb1-d0f5-3ed3f236ff0e@gentoo.org
In Reply to: Re: [gentoo-portage-dev] [PATCH] emerge-webrsync: use gkeys to verify gpg signatures (bug 597918) by Alexander Berntsen
1 On 10/27/2016 11:09 AM, Alexander Berntsen wrote:
2 > On 27/10/16 19:16, Zac Medico wrote:
3 >> Use gkeys to verify gpg signatures by default. Refresh the gentoo
4 >> snapshot signing key before signature verification, in order to
5 >> ensure that the latest revocation data is available. Add an
6 >> --insecure option which disables gpg signature verification. Warn
7 >> about man-in-the-middle attacks when the --insecure option is used.
8 >> Deprecate the pre-existing webrsync-gpg feature since it requires
9 >> manual gpg configuration.
10 > %s/ gpg/ OpenPGP/
11 >
12
13 Thanks, fixed.
14 --
15 Thanks,
16 Zac

Attachments

File name MIME type
signature.asc application/pgp-signature