|
From: Diego T. <dt...@co...> - 2004-02-09 18:35:24
|
On Sun, Feb 08, 2004 at 08:10:10PM -0500, Heiko Zuerker wrote: > >I mean how do you check the signature if the user did run custom-cd? > >How do we support security against tempering that way? > > Actually the user has to provide his own key pair. It's like the signing > of the etc.tar.bz2, the user has to burn his own public key onto the ISO > with custom-cd. i've been very busy and out for a while. is this gpg stuff configurable (with other words, can i take this feature off a custom build? :) -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dtorres at anthalia dot org - Madrid / España |