hzu...@ra... wrote on 12.01.2004 20:01 MET:
> On 01/12/2004 12:39:01 PM Friedrich Lobenstock wrote:
>
>>Bruce Smith wrote on 12.01.2004 17:49 MET:
>>
>>>>>>>another questions, are there plans to sign the source packages ????
>>>>>>>only a litte but important thing :-)
>>>>>>
>>>>>>Maybe we should at least do md5sums automatically in the update
>>
>>script.
>>
>>>>>>That should be enough for now I think.
>>>>>
>>>>>
>>>>>Good idea
>>>>
>>>>Already filed a feature request.
>>>>
>>>>I think the best way is that we create for eg. archive.tar.bz2
>>>>a file archive.tar.bz2.md5sum. This was we can easily automate
>>>>the task of checking every file while at the same time decoupling
>>>>it from one single ftp maintainer who would create on big md5sum
>>>>file for all files.
>>>
>>>
>>>While this is a great idea to ensure the downloads are good, it does
>>>nothing to prevent what happened at Debian. If someone breaks into
>>
>>the
>>
>>>FTP site, they can easily create a new md5sum file after they change
>>
>>the
>>
>>>source code. We really need some kind of a signed file to prevent
>>>that. Or at least keep the md5sum files on a different server.
>>
>>Than every developer who can upload files to the ftp server needs
>>to sign each md5sum file he uploads, right?.
>>
>>That would mean GPG needs to be installed in the lfs system right
>
>>from the beginning. The kexring can't be in CVS either, so that
>
>>would mean at start a developer has to initialize the keyring with
>>all the GPG/PGP public certificates. It always get's more
>>complicated...
>
>
> GPG signing is just too much work, especially the handling of the private
> key.
> We can't put it in CVS, because otherwise everybody can sign the files.....
Of course not, but we can put the keyrings with our public
keys in there and also the trust database file.
> What's about this simple idea:
> we add a new file to the CVS repository with this format:
> filename md5sum
>
> One line per source file.
> When we upload a file to the FTP Server, we have to create the checksum and
> update the file.
> update_src checks the checksum and warns if it is wrong or missing.
Then you have to update this file from CVS every time you
get new sources. I would rather stay with the signed md5sum
file per archive file.
Your way is of course also possible, but I would than say that
you have a second file which keeps the gpg signature of this file
so we are really sure.
--
MfG / Regards
Friedrich Lobenstock
____________________________________________________________________
Friedrich Lobenstock Linux Services Lobenstock
URL: http://www.lsl.at/ Email: fl...@fl...
____________________________________________________________________
|