Re: Signing releases with PGP
| From: | Stig S. Bakken | Date: | Wed, 29 May 2002 12:06:43 +0000 |
| Subject: | Re: Signing releases with PGP | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6588@lists.php.net to get a copy of this message | ||
On Wed, 2002-05-29 at 10:28, Markus Fischer wrote:
> Hi,
>
> this is just an idea, but with more and more packages getting
> into it, a infrastructure for providing authenticity should
> be considered ...
>
> I'm just thinking about what happened to the irsii sources
> lately...
>
> Neverthless it would be a good idea.
We have pgp key fields in the user database already. What about this:
In addition to package.xml, a package tarball will also contain
package.asc (or package.sig or whatever) which is a gpg signature of
package.xml. During "pear package", md5 checksums of all files are
added package.xml, so signing just that file and validating before
installing will be pretty safe.
AFAIK all of group@php.net have signed eachothers keys on the public pgp
keyservers, we could use that as a trust matrix starting point. It's
better to use public keyservers than to roll our own version, as long as
we have registered peoples' key ids.
- Stig