public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] GPG Signed packages
@ 2003-11-22  2:09 Yi Qiang
  2003-11-22  4:38 ` Lisa Seelye
  0 siblings, 1 reply; 7+ messages in thread
From: Yi Qiang @ 2003-11-22  2:09 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 741 bytes --]

I think this has been brought up many times before, but as most of us
know, many of the debian servers have been compromised recently.  This
has reinstated fear into many people about how "trustful" our distfile
repositories really are.  If indeed one is compromised it would be too
easy for someone to slip a backdoor into a package, especially since I
and a lot of other gentoo users simply ignore md5 checksums.  If a
digest fails we simply ebuild foo.ebuild digest it again.  I think an
option should be made that would allow failing packages if gpg fails. (I
think Redhat does something like this)  This of course is not a fool
proof way, but a big improvement over what is currently done to ensure
package integrity. 

Yi

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2003-11-23 10:44 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-22  2:09 [gentoo-dev] GPG Signed packages Yi Qiang
2003-11-22  4:38 ` Lisa Seelye
2003-11-22  5:24   ` Andrew Gaffney
2003-11-22  9:13   ` Torsten Veller
2003-11-22 13:15   ` James Harlow
2003-11-22 22:45     ` Aron Griffis
2003-11-23 10:45       ` Frank Zschockelt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox