Dnia 2015-05-16, o godz. 23:48:01 Alon Bar-Lev <alo...@gentoo.org> napisał(a):
> On 15 May 2015 at 17:51, Michał Górny <mgo...@gentoo.org> wrote: > > Please note that the current syncing code does not verify the OpenPGP > > signature to confirm the authenticity of fetched snapshots and deltas. > > This feature will be added as soon as gentoo-keys support in Portage is > > available. > > These are great news! > We can retire the webrsync. > Why not sign it similar to the portage snapshot are signed for now? > The webrsync signature validation is quite simple. All signing is in place already for a long time. Just the verification code is missing, and it wasn't added because I was told to wait for gentoo-keys. > Just a reminder: please note the rollback prevention mechanism in > webrsync, it is not enough to check signature, but also prevent older > snapshot to be used. Truth be told, the squashdelta syncing wasn't really made with rollback prevention in mind. I can't think immediately of any solution that would prevent accidental rollback while preserving the intended flexibility. -- Best regards, Michał Górny
pgptMxdy9Z1rN.pgp
Description: OpenPGP digital signature