public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] integrity of stage files
@ 2011-10-08 21:45 "Paweł Hajdan, Jr."
  2011-10-08 22:43 ` Robin H. Johnson
  0 siblings, 1 reply; 9+ messages in thread
From: "Paweł Hajdan, Jr." @ 2011-10-08 21:45 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 477 bytes --]

I checked
<http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?part=1&chap=5>
and the Handbook only mentions validating MD5 checksums.

There are two possible issues:

1. Why are we using _only_ MD5 and SHA1 as the checksums? Shouldn't we
be using something stronger?

2. I noticed the checksums are signed (.asc files). With what key are
they signed? How is that key handled, and how to ensure people use the
right key when verifying the signature?

Paweł


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 203 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2011-10-09  0:52 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-10-08 21:45 [gentoo-dev] integrity of stage files "Paweł Hajdan, Jr."
2011-10-08 22:43 ` Robin H. Johnson
2011-10-08 23:39   ` "Paweł Hajdan, Jr."
2011-10-09  0:01     ` Robin H. Johnson
2011-10-09  0:41       ` "Paweł Hajdan, Jr."
2011-10-09  0:44         ` Alec Warner
2011-10-09  0:51           ` Robin H. Johnson
2011-10-09  0:21   ` Matt Turner
2011-10-09  0:31     ` Robin H. Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox