|
From: Bruce S. <bw...@ar...> - 2004-01-12 16:49:36
|
> >>>another questions, are there plans to sign the source packages ???? > >>>only a litte but important thing :-) > >> > >>Maybe we should at least do md5sums automatically in the update script. > >>That should be enough for now I think. > > > > > > Good idea > > Already filed a feature request. > > I think the best way is that we create for eg. archive.tar.bz2 > a file archive.tar.bz2.md5sum. This was we can easily automate > the task of checking every file while at the same time decoupling > it from one single ftp maintainer who would create on big md5sum > file for all files. While this is a great idea to ensure the downloads are good, it does nothing to prevent what happened at Debian. If someone breaks into the FTP site, they can easily create a new md5sum file after they change the source code. We really need some kind of a signed file to prevent that. Or at least keep the md5sum files on a different server. - BS |