Re: Signing releases with PGP
| From: | Martin Jansen | Date: | Wed, 29 May 2002 12:36:39 +0000 |
| Subject: | Re: Signing releases with PGP | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6593@lists.php.net to get a copy of this message | ||
On 29 May 2002 14:06:43 +0200, Stig S. Bakken wrote:
>On Wed, 2002-05-29 at 10:28, Markus Fischer wrote:
>> Hi,
>>
>> this is just an idea, but with more and more packages getting
>> into it, a infrastructure for providing authenticity should
>> be considered ...
>>
>> I'm just thinking about what happened to the irsii sources
>> lately...
>>
>> Neverthless it would be a good idea.
>
>We have pgp key fields in the user database already. What about this:
>
>In addition to package.xml, a package tarball will also contain
>package.asc (or package.sig or whatever) which is a gpg signature of
>package.xml. During "pear package", md5 checksums of all files are
>added package.xml, so signing just that file and validating before
>installing will be pretty safe.
+1. I can add the md5 checksum system to "pear package" if noone
else wants to do it!?
>AFAIK all of group@php.net have signed eachothers keys on the public pgp
>keyservers, we could use that as a trust matrix starting point.
We could have a pear-group@php.net instead, if there are some people
on this list that don't trust Rasmus, Andrei, or you :-).
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/