Re: Signing releases with PGP

From: Date: Wed, 29 May 2002 12:36:39 +0000
Subject: Re: Signing releases with PGP
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6593@lists.php.net to get a copy of this message
On 29 May 2002 14:06:43 +0200, Stig S. Bakken wrote: >On Wed, 2002-05-29 at 10:28, Markus Fischer wrote: >> Hi, >> >> this is just an idea, but with more and more packages getting >> into it, a infrastructure for providing authenticity should >> be considered ... >> >> I'm just thinking about what happened to the irsii sources >> lately... >> >> Neverthless it would be a good idea. > >We have pgp key fields in the user database already. What about this: > >In addition to package.xml, a package tarball will also contain >package.asc (or package.sig or whatever) which is a gpg signature of >package.xml. During "pear package", md5 checksums of all files are >added package.xml, so signing just that file and validating before >installing will be pretty safe. +1. I can add the md5 checksum system to "pear package" if noone else wants to do it!? >AFAIK all of group@php.net have signed eachothers keys on the public pgp >keyservers, we could use that as a trust matrix starting point. We could have a pear-group@php.net instead, if there are some people on this list that don't trust Rasmus, Andrei, or you :-). - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#6593) next »