Dnia 2015-05-16, o godz. 23:48:01
Alon Bar-Lev <alo...@gentoo.org> napisał(a):

> On 15 May 2015 at 17:51, Michał Górny <mgo...@gentoo.org> wrote:
> > Please note that the current syncing code does not verify the OpenPGP
> > signature to confirm the authenticity of fetched snapshots and deltas.
> > This feature will be added as soon as gentoo-keys support in Portage is
> > available.
> 
> These are great news!
> We can retire the webrsync.
> Why not sign it similar to the portage snapshot are signed for now?
> The webrsync signature validation is quite simple.

All signing is in place already for a long time. Just the verification
code is missing, and it wasn't added because I was told to wait for
gentoo-keys.

> Just a reminder: please note the rollback prevention mechanism in
> webrsync, it is not enough to check signature, but also prevent older
> snapshot to be used.

Truth be told, the squashdelta syncing wasn't really made with rollback
prevention in mind. I can't think immediately of any solution that
would prevent accidental rollback while preserving the intended
flexibility.

-- 
Best regards,
Michał Górny

Attachment: pgptMxdy9Z1rN.pgp
Description: OpenPGP digital signature

Reply via email to