From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1RChVJ-0004B0-SD for garchives@archives.gentoo.org; Sun, 09 Oct 2011 00:44:34 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id C9AC621C191; Sun, 9 Oct 2011 00:44:25 +0000 (UTC) Received: from mail-vw0-f53.google.com (mail-vw0-f53.google.com [209.85.212.53]) by pigeon.gentoo.org (Postfix) with ESMTP id DB8F421C2B5 for ; Sun, 9 Oct 2011 00:44:01 +0000 (UTC) Received: by vws19 with SMTP id 19so6636605vws.40 for ; Sat, 08 Oct 2011 17:44:01 -0700 (PDT) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 Received: by 10.52.64.169 with SMTP id p9mr8084606vds.99.1318121041366; Sat, 08 Oct 2011 17:44:01 -0700 (PDT) Sender: antarus@scriptkitty.com Received: by 10.52.163.38 with HTTP; Sat, 8 Oct 2011 17:44:01 -0700 (PDT) In-Reply-To: <4E90EDCD.9060907@gentoo.org> References: <4E90C45E.7020203@gentoo.org> <4E90DF3C.8030307@gentoo.org> <4E90EDCD.9060907@gentoo.org> Date: Sat, 8 Oct 2011 17:44:01 -0700 X-Google-Sender-Auth: 26u15ZvJAtxQdm9AWKPVz7jhYY0 Message-ID: Subject: Re: [gentoo-dev] integrity of stage files From: Alec Warner To: gentoo-dev@lists.gentoo.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Archives-Salt: X-Archives-Hash: f78574a2443d8c67af466e0fa05d120f On Sat, Oct 8, 2011 at 5:41 PM, "Pawe=C5=82 Hajdan, Jr." wrote: > On 10/8/11 5:01 PM, Robin H. Johnson wrote: >>> Ah, I just forgot about that page. Okay, so can we also update the >>> Handbook to include GPG signature checking? >> It DOES already mention checking the signature: >> http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=3D1&chap=3D2= #doc_chap3 > > That's good, but it only mentions GPG for checking downloaded .iso > images. GPG is not mentioned at all for stage files. > > For example, I don't re-download the installation .iso very often (old > ones are still good, or one can use sysresccd), but I always re-download > the most recent stages (less rebuilding). > > Why not ship something in /usr/portage/scripts, or write some scripts to do this? -A