On Sat, May 20, 2006 at 06:54:44AM -0400, Peter wrote: > On Thu, 18 May 2006 23:45:17 +0200, Patrick Lauer wrote: > > >The problem, in short, is how to handle the checksumming and signing of > >gentoo-provided files so that manipulation by external entities becomes > >difficult. > all snip... > > PMFJI, but as a user, not a security expert, I had a few thoughts that I'd > like to throw in. Thanks to Patrick, he helped me to drill down some of > the ideas and I present them for consideration. It's just a framework, so > I will be brief. Even larger snip. I was actually looking at something similar to this, for the 'simple' portion of Patrick's plan. You have most of the major ideas down, but missed a few holes, and sticking points. I'll try to get a writeup of it out later tonight, got a double-date first ;-). Thanks for the good writeup of Slackware as well, it's one I didn't elaborate much on when I previously described the processes of RPM-distros and Debian. -- Robin Hugh Johnson E-Mail : robbat2@gentoo.org GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85