[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Checking signatures on source tarballs
From: |
Ludovic Courtès |
Subject: |
Re: Checking signatures on source tarballs |
Date: |
Mon, 12 Oct 2015 18:39:36 +0200 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux) |
Brandon Invergo <address@hidden> skribis:
> Hi everyone,
>
> On Thu, 2015-10-08 at 13:44 +0200, Ludovic Courtès wrote:
>
>> Actually I see that GSRC already maintains per-package keyrings.
>>
>> How is this maintained, Brandon? That is, where do you get information
>> on which keys to put in the keyring, etc.?
>
> Admittedly, it's not ideal. When we first add a package, we make a
> keyring for it based on whatever information is available to us.
> Sometimes the public key is listed in the release announcement. Other
> times, we just have to grab the public key of whatever we see the
> package was signed with. Obviously, that's not very secure since it
> could have been signed by an attacker. However usually this process is
> only performed when adding a new (to GNU) package. Then, if the
> signature-checking process ever fails on future releases, I actually
> look into it. Sometimes, no public key is available in any of the key
> servers as far as I can tell. In those cases, we ignore the signature.
OK. That’s roughly what Mark suggests that we do in Guix, an
improvement over the current situation.
Thanks for your feedback!
Ludo’.
- Re: Checking signatures on source tarballs, (continued)
- Re: Checking signatures on source tarballs, Leo Famulari, 2015/10/08
- Re: Checking signatures on source tarballs, Ludovic Courtès, 2015/10/08
- Re: Checking signatures on source tarballs, Ludovic Courtès, 2015/10/09
- Re: Checking signatures on source tarballs, Brandon Invergo, 2015/10/15
- Re: [bug-gsrc] Checking signatures on source tarballs, Brandon Invergo, 2015/10/12
- Re: [bug-gsrc] Checking signatures on source tarballs, Ludovic Courtès, 2015/10/12
- Re: [bug-gsrc] Checking signatures on source tarballs, Brandon Invergo, 2015/10/15
- Re: [bug-gsrc] Checking signatures on source tarballs, Ludovic Courtès, 2015/10/12
- Re: [bug-gsrc] Checking signatures on source tarballs, Brandon Invergo, 2015/10/12
- Re: [bug-gsrc] Checking signatures on source tarballs, Ludovic Courtès, 2015/10/15
- Re: Checking signatures on source tarballs,
Ludovic Courtès <=
- Re: Checking signatures on source tarballs, Alex Vong, 2015/10/10
- Re: Checking signatures on source tarballs, Mark H Weaver, 2015/10/10
- Re: Checking signatures on source tarballs, Ludovic Courtès, 2015/10/11
- Re: Checking signatures on source tarballs, Rastus Vernon, 2015/10/15
- Re: Checking signatures on source tarballs, Mark H Weaver, 2015/10/15
- Re: Checking signatures on source tarballs, Alex Kost, 2015/10/08
- Re: Checking signatures on source tarballs, Andreas Enge, 2015/10/08
[PATCH 1/4] emacs: Add 'guix-devel-with-definition'., Alex Kost, 2015/10/08