From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 4890 invoked from network); 8 Nov 2004 20:06:21 +0000 Received: from smtp.gentoo.org (156.56.111.197) by lists.gentoo.org with AES256-SHA encrypted SMTP; 8 Nov 2004 20:06:21 +0000 Received: from lists.gentoo.org ([156.56.111.196] helo=parrot.gentoo.org) by smtp.gentoo.org with esmtp (Exim 4.41) id 1CRFmP-0006k8-1c for arch-gentoo-security@lists.gentoo.org; Mon, 08 Nov 2004 20:06:21 +0000 Received: (qmail 6867 invoked by uid 89); 8 Nov 2004 20:05:57 +0000 Mailing-List: contact gentoo-security-help@gentoo.org; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-security@gentoo.org Received: (qmail 30412 invoked from network); 8 Nov 2004 20:05:57 +0000 Date: Mon, 8 Nov 2004 21:05:52 +0100 From: Marius Mauch To: gentoo-security@lists.gentoo.org Message-ID: <20041108210552.6923a7fd@sven.genone.homeip.net> In-Reply-To: <87acttqcz1.fsf_-_@peti.cryp.to> References: <418D310B.6050106@ahsoftware.de> <20041106193125.A24826@netdirect.ca> <20041107152350.GF10927@mail.lieber.org> <87d5ypu0in.fsf@peti.cryp.to> <87acttqcz1.fsf_-_@peti.cryp.to> Organization: Gentoo Linux X-Mailer: Sylpheed-Claws 0.9.12b (GTK+ 1.2.10; i686-pc-linux-gnu) X-Face: H@&[wkk?l:Zx:8i_5bViK&{Vz{c{~r),^&:v/r#+X5dmfA6qCl)~'Ul{"&06Q1[05.%v&c>je5R{=xLnx^=~lN~rO0xuR~~NY)CX\"Nc4$9CBPwDl-.pYuVeGdir86L@\:j?7@%Ej2?Wi-Y0=1]T14ce0w79Bckk[*ti{;iA"{;I}&E~.msRBsBS)N!CS4Gd|_UR Mime-Version: 1.0 Content-Type: multipart/signed; protocol="application/pgp-signature"; micalg="pgp-sha1"; boundary="Signature=_Mon__8_Nov_2004_21_05_52_+0100_DG1jqUunch8EQunN" X-Provags-ID: kundenserver.de abuse@kundenserver.de auth:7e6c91d1b14dbccceb2f2166522fa0f6 Subject: Re: [gentoo-security] How to authenticate the portage tree X-Archives-Salt: 9e3e6998-2f0f-4b2f-a061-b17c80768664 X-Archives-Hash: d52703e469e11763ddc9cd2eb2fce3b2 --Signature=_Mon__8_Nov_2004_21_05_52_+0100_DG1jqUunch8EQunN Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: 7bit On 08 Nov 2004 03:41:22 +0100 Peter Simons wrote: > (1) Run "find /usr/portage -type f | xargs sha1sum -b" on > the Gentoo main system. What's the 'Gentoo main system'? > (2) Sign the output with GPG. Who does that? Basically we do that already with Manifests, just that they don't cover the whole tree (yet). Marius -- Public Key at http://www.genone.de/info/gpg-key.pub In the beginning, there was nothing. And God said, 'Let there be Light.' And there was still nothing, but you could see a bit better. --Signature=_Mon__8_Nov_2004_21_05_52_+0100_DG1jqUunch8EQunN Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBj9GkWzrL1pM7SNcRAuhIAJ9jGUTvPZpro2llrS6+AygRBUlZ3ACfROBd MXIletAajLR9olUphFcDLlI= =+2lQ -----END PGP SIGNATURE----- --Signature=_Mon__8_Nov_2004_21_05_52_+0100_DG1jqUunch8EQunN--