Re: Signing releases with PGP

From: Date: Wed, 29 May 2002 12:06:43 +0000
Subject: Re: Signing releases with PGP
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6588@lists.php.net to get a copy of this message
On Wed, 2002-05-29 at 10:28, Markus Fischer wrote: > Hi, > > this is just an idea, but with more and more packages getting > into it, a infrastructure for providing authenticity should > be considered ... > > I'm just thinking about what happened to the irsii sources > lately... > > Neverthless it would be a good idea. We have pgp key fields in the user database already. What about this: In addition to package.xml, a package tarball will also contain package.asc (or package.sig or whatever) which is a gpg signature of package.xml. During "pear package", md5 checksums of all files are added package.xml, so signing just that file and validating before installing will be pretty safe. AFAIK all of group@php.net have signed eachothers keys on the public pgp keyservers, we could use that as a trust matrix starting point. It's better to use public keyservers than to roll our own version, as long as we have registered peoples' key ids. - Stig

« previous php.pear.dev (#6588) next »