From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1Q3LAa-0003CT-RV for garchives@archives.gentoo.org; Sat, 26 Mar 2011 04:32:13 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 07F011C00F; Sat, 26 Mar 2011 04:31:57 +0000 (UTC) Received: from mail.caf.com.tr (mail.caf.com.tr [88.250.85.68]) by pigeon.gentoo.org (Postfix) with ESMTP id 4BB971C001 for ; Sat, 26 Mar 2011 04:31:29 +0000 (UTC) Received: from localhost (mta.caf.com.tr [10.0.2.208]) by mail.caf.com.tr (Postfix) with ESMTP id 397FA8493C for ; Sat, 26 Mar 2011 04:31:28 +0000 (UTC) X-Virus-Scanned: amavisd-new at caf.com.tr Received: from mail.caf.com.tr ([10.0.2.205]) by localhost (check.caf.com.tr [10.0.2.205]) (amavisd-new, port 10026) with ESMTP id 0RIQEDQefJEy for ; Sat, 26 Mar 2011 04:31:27 +0000 (UTC) Received: from [46.154.159.5] (unknown [46.154.159.5]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.caf.com.tr (Postfix) with ESMTPSA id A209F83301 for ; Sat, 26 Mar 2011 04:31:27 +0000 (UTC) Message-ID: <4D8D6C0D.5070807@gentoo.org> Date: Sat, 26 Mar 2011 06:31:09 +0200 From: Eray Aslan User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.15) Gecko/20110303 Mnenhy/0.8.3 Thunderbird/3.1.9 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 To: gentoo-dev@lists.gentoo.org Subject: Re: [gentoo-dev] rejecting unsigned commits References: <4D8C82B9.5070309@gentoo.org> <4D8C83B5.5040600@gentoo.org> In-Reply-To: <4D8C83B5.5040600@gentoo.org> X-Enigmail-Version: 1.1.1 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------enig9C259A7EB74C00F97F8DB6AE" X-Archives-Salt: X-Archives-Hash: 6b7bb6a68d56d4af1b0c596f4153eb9c This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig9C259A7EB74C00F97F8DB6AE Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On 2011-03-25 1:59 PM, Dane Smith wrote: > Having said that, for those that just use "keys" for e-mails (most of > us), it would make more sense to use full blow SSL certs in the long ru= n. Please no. PKI is a naive design and for all intents and purposes will remain a pipe-dream. All security relationships that is worth anything is bilateral and no trusted third party is willing to accept enough risk to warrent full trust. Using public keys for auth is a good security model and the rest of x509 certs is just unnecessary overhead. Let's not go there. GPG is good enough. --=20 Eray Aslan Developer, Gentoo Linux eras gentoo.org --------------enig9C259A7EB74C00F97F8DB6AE Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQIcBAEBCAAGBQJNjWwXAAoJEHfx8XVYajsfuBMQAJt2yqY2Y1h/9AoYGcdNXEG8 nRsGLVPs+DY4zglZEqvRmQlEZ6hNf4dy0qMLzqvgSmHxZtTKBWtzLhaI4JZ4U4QA hY6Cj1kmMoW5I9/XX49gY7hGqjZYuXmozA0TwOcB9pY3xg4dP4qkqyrn3YPKl4n7 zqKyN47GcMdgo1C6WqVteJHvcGYxvwiKzhXYtO4A9+9Oc2QHwkKCN3RoPqqw2tV7 UwA4yW7dWF4m9wlcm0cnjPSejBAfckaTrfn+MvDTbsGuqQeyJQX5nD2ouOUeT4sM x1OTlos4HIe/ss9gC1aNlYIwboDIxDNiXIhuNbdWV0oN30FXRkURuqARGgZk9yzw qUNePEyv7pbR7e048L8wl27mo9Xzh0bfKj5fctErU9RuaFcBDMRA4tF+2RH+yc+b rYDs4bCk3VljJnQMjPCA3denf0/M54Di5ywFAnlQAk5m3XzX7Og1ddK2v4BBZmko wPv5Dsn8s7N6/lkCBRLB0d+09MuXKCprVxkv28qZTvUf7Vn8D28NeRVZEzG28g71 hDJU8YH/ItD5jR//+Vk7W4FP5JU/yDZxCy/pWUPsId28NlKme2KWoQHrfT+9mp+K t41tVYd0EHaTbNOHN/azVymZTYK5aqd0fauUlmzJsaGCEYufwHa3k+LQ9Y2Tgf60 N4sUKEKfwI9S7gfsuik5 =lYBC -----END PGP SIGNATURE----- --------------enig9C259A7EB74C00F97F8DB6AE--