Gentoo Archives: gentoo-portage-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-portage-dev@l.g.o
Subject: [gentoo-portage-dev] proto-GLEPS for Tree-signing, take 2
Date: Sat, 12 Jul 2008 08:42:48
Message-Id: 20080712084258.GC31199@curie-int.orbis-terrarum.net
So I'm not going to directly attach the GLEPs again this time, however
I am just going to link to them, and summarize the changes:

xx+1:
- Add mention of how to defeat the mirror replay attacks from Stork@UArizona.
- Clarify wording of the UNCOVERED=ALL-COVERED set math, and why it's
  important (genone)
- Add a timestamp to the metamanifest.
- Mention that it can be implemented without the new Manifest2
  filetypes.

xx+5:
- Update the exclusion lists.
- Exclusion list behavior during strict validation.
- Fix typos.

prototype/generate-metamanifest.py:
- Prototype of the MetaManifest generation.
- Doesn't sign yet, but does include the timestamp.
- Uses existing Manifest2 types.
- See header for existing runtime info - it's quite fast.

http://sources.gentoo.org/viewcvs.py/gentoo/users/robbat2/tree-signing-gleps/

I'd like to ask for any comments to be in to me by July 14th 23:59UTC.
After that I'd like to post the GLEPs to the gentoo-dev mailing list.

-- 
Robin Hugh Johnson
Gentoo Linux Developer & Infra Guy
E-Mail     : robbat2@g.o
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

Replies

Subject Author
Re: [gentoo-portage-dev] proto-GLEPS for Tree-signing, take 2 Zac Medico <zmedico@g.o>