Re: Signing packages
| From: | Paul Cooper | Date: | Fri, 20 Jun 2003 22:54:17 +0000 |
| Subject: | Re: Signing packages | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-17607@lists.php.net to get a copy of this message | ||
On Fri, 2003-06-20 at 23:38, Jesus M. Castagnetto wrote:
> As a side-thread to the PECL packaging discussion.
>
> There is the option in 'pear' to use gpg to sign package releases, but one
> thing we do not have is a PEAR web of trust for the keys. Usually people will
> sing other people's keys in 'Key signing parties' to generate that web of trust
> (http://www.cryptnet.net/fdp/crypto/gpg-party.html).
>
> It will not be trivial to get all keys signed and in a PEAR 'web of trust', as
> usually the mutual signings are supposed to happen on a face to face meeting of
> the people doing the signing.
>
> Ideas? Comments?
Well if I understand these things correctly, once the web is started we
just have to have key signing parties at every relevant conference
(OSCON, Linuxworld, UKUUG, PHP Conference, etc) or gatherings (LUGS, PHP
UGS) or face to face meetings.
Paul
>
> =====
> --
> Jesus M. Castagnetto (jcastagnetto@yahoo.com)
> Research: http://metallo.scripps.edu/
> Personal: http://www.castagnetto.org/
>
> __________________________________
> Do you Yahoo!?
> SBC Yahoo! DSL - Now only $29.95 per month!
> http://sbc.yahoo.com