1 |
On Thu, 27 Oct 2016 10:16:42 -0700 |
2 |
Zac Medico <zmedico@g.o> wrote: |
3 |
|
4 |
> Use gkeys to verify gpg signatures by default. Refresh the gentoo |
5 |
> snapshot signing key before signature verification, in order to ensure |
6 |
> that the latest revocation data is available. Add an --insecure option |
7 |
> which disables gpg signature verification. Warn about |
8 |
> man-in-the-middle attacks when the --insecure option is used. |
9 |
> Deprecate the pre-existing webrsync-gpg feature since it requires |
10 |
> manual gpg configuration. |
11 |
> |
12 |
> X-Gentoo-Bug: 597918 |
13 |
> X-Gentoo-Bug-URL: https://bugs.gentoo.org/show_bug.cgi?id=597918 |
14 |
> --- |
15 |
> bin/emerge-webrsync | 51 |
16 |
> +++++++++++++++++++++++++++++++++++++++++++++++---- |
17 |
> man/make.conf.5 | 6 ++++-- 2 files changed, 51 insertions(+), 6 |
18 |
> deletions(-) |
19 |
> |
20 |
|
21 |
LGTM |
22 |
|
23 |
-- |
24 |
Brian Dolbec <dolsen> |