|
From: Bruce S. <bw...@ar...> - 2004-01-12 18:29:16
|
> > While this is a great idea to ensure the downloads are good, it does > > nothing to prevent what happened at Debian. If someone breaks into the > > FTP site, they can easily create a new md5sum file after they change the > > source code. We really need some kind of a signed file to prevent > > that. Or at least keep the md5sum files on a different server. > > Than every developer who can upload files to the ftp server needs > to sign each md5sum file he uploads, right?. Probably be easier than signing the tar files. :-) > That would mean GPG needs to be installed in the lfs system right > from the beginning. Or on the host Linux, especially since you can't download the source from within the LFS chroot anyway. We could make GPG required on the host Linux, like lftp. > The kexring can't be in CVS either, Why not? It's a different server. Different access/passwords, and if someone changed it, we'd be notified by email on the commit list. > so that would mean at start a developer has to initialize the keyring > with all the GPG/PGP public certificates. Maybe the keys could be installed on the local system once? Redhat does it something like that with their RPM's. You download the keys once, which are installed on the local Redhat system. Then RPM automatically checks the signatures when installing a RPM file. This is all just theory on my part, since I've never actually setup anything like this. Feel free to blow holes in my ideas. > It always get's more complicated... I didn't say it would be easy!!! ;-) Just pointing out that md5sum does not solve the original concern. - BS |