Signing packages
| From: | Jesus M. Castagnetto | Date: | Fri, 20 Jun 2003 22:38:17 +0000 |
| Subject: | Signing packages | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-17606@lists.php.net to get a copy of this message | ||
As a side-thread to the PECL packaging discussion.
There is the option in 'pear' to use gpg to sign package releases, but one
thing we do not have is a PEAR web of trust for the keys. Usually people will
sing other people's keys in 'Key signing parties' to generate that web of trust
(http://www.cryptnet.net/fdp/crypto/gpg-party.html).
It will not be trivial to get all keys signed and in a PEAR 'web of trust', as
usually the mutual signings are supposed to happen on a face to face meeting of
the people doing the signing.
Ideas? Comments?
=====
--
Jesus M. Castagnetto (jcastagnetto@yahoo.com)
Research: http://metallo.scripps.edu/
Personal: http://www.castagnetto.org/
__________________________________
Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
http://sbc.yahoo.com