Name | Modified | Size | Downloads / Week |
---|---|---|---|
Parent folder | |||
9.3 | 2024-01-23 | ||
9.2 | 2024-01-23 | ||
9.1 | 2024-01-23 | ||
readme.txt | 2024-01-23 | 1.3 kB | |
Totals: 4 Items | 1.3 kB | 0 |
NetBSD can use both GPG and X509 certificates for validating packages. With X509 need a CERTIFICATE_ANCHOR_PKGS entry to /etc/pkg_install.conf to point to a text file containing a list of PEM format root/CA certificates. For example $ cat /etc/pkg_install.conf PKG_PATH=https://ftp.NetBSD.org/pub/pkgsrc/packages/NetBSD/aarch64/9.1/All/ CERTIFICATE_ANCHOR_PKGS=/usr/pkg/etc/pkgin/trustChain.pem The CA used for these signatures is for Subject: CN = rhubarb-geek-nz CA The certificate is on user rhubarb-geek-nz sourcforge personal wiki. https://sourceforge.net/u/rhubarb-geek-nz/wiki/Home/ This shows that a package is signed $ ar t cdesktopenv-2.3.2b.f294ef4apl1.tgz +PKG_HASH +PKG_SIGNATURE cdesktopenv-2.3.2b.f294ef4apl1.tgz Validating a package can be done with pkg_info $ pkg_info cdesktopenv-2.3.2b.f294ef4apl1.tgz | head Sigature ok, signed by: /emailAddress=rhubarb-geek-nz@users.sourceforge.net/CN=rhubarb-geek-nz Information for cdesktopenv-2.3.2b.f294ef4apl1.tgz: Comment: CDE - Common Desktop Environment Requires: ast-ksh freetype2