|
From: <hzu...@ra...> - 2004-02-09 18:53:27
|
On 02/09/2004 01:34:21 PM Diego Torres wrote: >On Sun, Feb 08, 2004 at 08:10:10PM -0500, Heiko Zuerker wrote: > >> >I mean how do you check the signature if the user did run custom-cd? >> >How do we support security against tempering that way? >> >> Actually the user has to provide his own key pair. It's like the >signing >> of the etc.tar.bz2, the user has to burn his own public key onto the >ISO >> with custom-cd. > >i've been very busy and out for a while. is this gpg stuff configurable >(with other words, can i take this feature off a custom build? :) Do you mean to turn it off ? It's only active when you custom-cd you ISO image and put your public key onto the CD. Heiko |