|
From: Friedrich L. <fl...@fl...> - 2004-01-12 19:15:48
|
Bruce Smith wrote on 12.01.2004 19:29 MET: >>>While this is a great idea to ensure the downloads are good, it does >>>nothing to prevent what happened at Debian. If someone breaks into the >>>FTP site, they can easily create a new md5sum file after they change the >>>source code. We really need some kind of a signed file to prevent >>>that. Or at least keep the md5sum files on a different server. >> >>Than every developer who can upload files to the ftp server needs >>to sign each md5sum file he uploads, right?. > > > Probably be easier than signing the tar files. :-) > > >>That would mean GPG needs to be installed in the lfs system right >>from the beginning. > > > Or on the host Linux, especially since you can't download the source > from within the LFS chroot anyway. You can for sure download chrooted to the lfs system. You probably have to copy your /etc/resolv.conf to corresponding directory of the lfs system. Done that for a long time. So the only commands we need from the host Linux are basically chroot, cvs, diff and ssh. > We could make GPG required on the host Linux, like lftp. If we have it in the lfs system everybody has for sure the same environment. >>The kexring can't be in CVS either, > > > Why not? It's a different server. Different access/passwords, and > if someone changed it, we'd be notified by email on the commit list. Ok, good point, so lets put it there. >>so that would mean at start a developer has to initialize the keyring >>with all the GPG/PGP public certificates. > > > Maybe the keys could be installed on the local system once? > > Redhat does it something like that with their RPM's. You download the > keys once, which are installed on the local Redhat system. Then RPM > automatically checks the signatures when installing a RPM file. > > This is all just theory on my part, since I've never actually setup > anything like this. Feel free to blow holes in my ideas. If the keyring is in CVS do a checkout or update and then chrooted to the lfs system now you should be able to use gpg. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |