diff options
Diffstat (limited to 'zarb-ml/mageia-dev/20110131/002400.html')
-rw-r--r-- | zarb-ml/mageia-dev/20110131/002400.html | 90 |
1 files changed, 90 insertions, 0 deletions
diff --git a/zarb-ml/mageia-dev/20110131/002400.html b/zarb-ml/mageia-dev/20110131/002400.html new file mode 100644 index 000000000..c1522b441 --- /dev/null +++ b/zarb-ml/mageia-dev/20110131/002400.html @@ -0,0 +1,90 @@ +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> +<HTML> + <HEAD> + <TITLE> [Mageia-dev] PGP keys and package signing + </TITLE> + <LINK REL="Index" HREF="index.html" > + <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20PGP%20keys%20and%20package%20signing&In-Reply-To=%3C201101312040.00434.maarten.vanraes%40gmail.com%3E"> + <META NAME="robots" CONTENT="index,nofollow"> + <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> + <LINK REL="Previous" HREF="002395.html"> + <LINK REL="Next" HREF="002393.html"> + </HEAD> + <BODY BGCOLOR="#ffffff"> + <H1>[Mageia-dev] PGP keys and package signing</H1> + <B>Maarten Vanraes</B> + <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20PGP%20keys%20and%20package%20signing&In-Reply-To=%3C201101312040.00434.maarten.vanraes%40gmail.com%3E" + TITLE="[Mageia-dev] PGP keys and package signing">maarten.vanraes at gmail.com + </A><BR> + <I>Mon Jan 31 20:40:00 CET 2011</I> + <P><UL> + <LI>Previous message: <A HREF="002395.html">[Mageia-dev] PGP keys and package signing +</A></li> + <LI>Next message: <A HREF="002393.html">[Mageia-dev] PGP keys and package signing +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#2400">[ date ]</a> + <a href="thread.html#2400">[ thread ]</a> + <a href="subject.html#2400">[ subject ]</a> + <a href="author.html#2400">[ author ]</a> + </LI> + </UL> + <HR> +<!--beginarticle--> +<PRE>Op maandag 31 januari 2011 18:01:16 schreef nicolas vigier: +><i> On Mon, 31 Jan 2011, Christophe Fergeau wrote: +</I>><i> > 2011/1/31 nicolas vigier <<A HREF="https://www.mageia.org/mailman/listinfo/mageia-dev">boklm at mars-attacks.org</A>>: +</I>><i> > > On Sun, 30 Jan 2011, Motoko-chan wrote: +</I>><i> > >> What if urpmi automatically trusts packages signed with a key signed +</I>><i> > >> by board@ and prompt on the first install of a package that is signed +</I>><i> > >> by a different key? The yum tool used by Fedora, RHEL, and CentOS +</I>><i> > >> works very well by prompting on new keys. +</I>><i> > > +</I>><i> > > For PLF packages, they will now be included on Mageia repository, so +</I>><i> > > most users should not need to use external repositories. However we +</I>><i> > > can add an option or prompt to disable this check, or an option to +</I>><i> > > manually add a new trusted key. As long as it's not automatically +</I>><i> > > downloaded from the mirror without asking for any confirmation. +</I>><i> > +</I>><i> > You definitely want to let people set up their own local package +</I>><i> > repositories or to use 3rd party repositories, for example I did it +</I>><i> > sometimes at Mandriva for some tests, and I want to do it again for +</I>><i> > internal work/proprietary packages. I'm ok with having rpm/urpmi +</I>><i> > telling you you're about to install packages with an unknown +</I>><i> > signature/... as long as you can override it and tell it to let you +</I>><i> > install the package. +</I>><i> +</I>><i> Yes, we should add an option somewhere to allow this. +</I> +isn't it easier if local overrides would also provide a way to add keys that +can be validated, imo. + +I'm writing urpmi-proxy, and and i would like to have a good way to have local +overrides with their own key signed. + +perhaps if a diff key is detected, a certain procedure could be started that +could ask the user if this key is trusted or not, or refer to somewhere else? + +also, thinking on the upgrade path from Mandriva, i'm not sure how... +</PRE> + +<!--endarticle--> + <HR> + <P><UL> + <!--threads--> + <LI>Previous message: <A HREF="002395.html">[Mageia-dev] PGP keys and package signing +</A></li> + <LI>Next message: <A HREF="002393.html">[Mageia-dev] PGP keys and package signing +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#2400">[ date ]</a> + <a href="thread.html#2400">[ thread ]</a> + <a href="subject.html#2400">[ subject ]</a> + <a href="author.html#2400">[ author ]</a> + </LI> + </UL> + +<hr> +<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev +mailing list</a><br> +</body></html> |