Re: Signing releases with PGP

From: Date: Wed, 29 May 2002 13:12:59 +0000
Subject: Re: Signing releases with PGP
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6598@lists.php.net to get a copy of this message
On Wed, 2002-05-29 at 14:36, Martin Jansen wrote: > On 29 May 2002 14:06:43 +0200, Stig S. Bakken wrote: > > >On Wed, 2002-05-29 at 10:28, Markus Fischer wrote: > >> Hi, > >> > >> this is just an idea, but with more and more packages getting > >> into it, a infrastructure for providing authenticity should > >> be considered ... > >> > >> I'm just thinking about what happened to the irsii sources > >> lately... > >> > >> Neverthless it would be a good idea. > > > >We have pgp key fields in the user database already. What about this: > > > >In addition to package.xml, a package tarball will also contain > >package.asc (or package.sig or whatever) which is a gpg signature of > >package.xml. During "pear package", md5 checksums of all files are > >added package.xml, so signing just that file and validating before > >installing will be pretty safe. > > +1. I can add the md5 checksum system to "pear package" if noone > else wants to do it!? It's already there. Try: wget -O - http://pear.php.net/get/DB|tar -O -xvzf - package.xml|less - Stig

« previous php.pear.dev (#6598) next »