octal-dev
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

re: re: updates


From: amep
Subject: re: re: updates
Date: Sat Jan 20 18:33:01 2001

From: "Danny P." <address@hidden>
Subject: re: re: updates
Date: Sat, 20 Jan 2001 01:04:48 -0500

> >There is a step you may want add: GPG signing the source once it has
> >been audited. This would allow people to make sure the copy they have
> >is actually the one which was audited. This is probably not very
> >important now, but if and when there are mirrors it is possible that
> >there would be trojan mirrors. Just a thought.
> >
> >-Arthur
> 
> It isn't hard (there is a learning curve however) to do this and it's really 
> cool. I think it should be done from the start :)
> 

Yes, a small learning curve, but GPG is really very easy. Also, there
are GUI people could use.

I just found that GPG will search a file given as a signature file for
a signature block. So, we could just put it at the end text info
file. People could check it with a command like "gpg --verify pan.txt
pan.c" (given the plug-in is named "pan").

-Arthur

Attachment: pgp2xZ871VydI.pgp
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]