public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Manifest signing advice: use gpg-agent!
@ 2004-09-04 22:34 Tom Martin
  2004-09-05  7:20 ` Nicholas Jones
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Tom Martin @ 2004-09-04 22:34 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 861 bytes --]

Hiya guys,

As many devs are starting to GPG sign Manifests with repoman, there have been
inevitable problems with people putting their passphrase into the commit message. I've
*nearly* hit the return key on it a few times, and a certain other developer did
actually post their passphrase as a commit message. This, more than anything else, is a
real PITA and at least -fairly- embarassing...

In my opinion, it is a Very Good Thing to use a program such as quintuple-agent or
gpg-agent to keep your passphrase in protected memory to avoid such problems, if you
aren't doing so already.

app-crypt/newpg for gpg-agent
app-crypt/quintuple-agent for... err... quintuple-agent

Happy signing,
Tom

-- 
Tom Martin
Gentoo Linux AMD64 and net-mail developer

GPG Public key available on pgp.mit.edu, 0xB5C4FF89
IRC: slarti` ~ irc.freenode.net

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-09-07  0:32 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-09-04 22:34 [gentoo-dev] Manifest signing advice: use gpg-agent! Tom Martin
2004-09-05  7:20 ` Nicholas Jones
2004-09-05  9:22 ` Robin H. Johnson
2004-09-07  0:32 ` Mike Frysinger

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox