Re: Signing releases with PGP
| From: | Stig S. Bakken | Date: | Wed, 29 May 2002 13:12:59 +0000 |
| Subject: | Re: Signing releases with PGP | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6598@lists.php.net to get a copy of this message | ||
On Wed, 2002-05-29 at 14:36, Martin Jansen wrote:
> On 29 May 2002 14:06:43 +0200, Stig S. Bakken wrote:
>
> >On Wed, 2002-05-29 at 10:28, Markus Fischer wrote:
> >> Hi,
> >>
> >> this is just an idea, but with more and more packages getting
> >> into it, a infrastructure for providing authenticity should
> >> be considered ...
> >>
> >> I'm just thinking about what happened to the irsii sources
> >> lately...
> >>
> >> Neverthless it would be a good idea.
> >
> >We have pgp key fields in the user database already. What about this:
> >
> >In addition to package.xml, a package tarball will also contain
> >package.asc (or package.sig or whatever) which is a gpg signature of
> >package.xml. During "pear package", md5 checksums of all files are
> >added package.xml, so signing just that file and validating before
> >installing will be pretty safe.
>
> +1. I can add the md5 checksum system to "pear package" if noone
> else wants to do it!?
It's already there. Try:
wget -O - http://pear.php.net/get/DB|tar -O -xvzf -
package.xml|less
- Stig