Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Sébastien Luttringer
On 05/01/2015 10:09, Daniel Micay wrote: > On 04/01/15 04:05 PM, Christian Hesse wrote: > I would create a wiki page with the list and then see if you can find a > developer interested in mass-adding the missing signatures. I'd be > interested in helping with it for [community], but you'll likely b

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Leonid Isaev
On Mon, Jan 05, 2015 at 04:09:50AM -0500, Daniel Micay wrote: > On 04/01/15 04:05 PM, Christian Hesse wrote: > > Hello everybody, > > > > pacman 4.2.0 gained support for verifying source tarballs with kernel.org > > style signature. Some (even essential) packages could benefit from that, > > linux

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Daniel Micay
On 05/01/15 12:28 PM, Leonid Isaev wrote: > On Mon, Jan 05, 2015 at 10:16:10AM +0100, Christian Hesse wrote: >> I do not think we need HTTPS, though it does not hurt. If anybody tries to >> fool us with man-in-the-middle via HTTP we should detect that just fine with >> broken signatures (given sign

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Leonid Isaev
On Mon, Jan 05, 2015 at 10:16:10AM +0100, Christian Hesse wrote: > I do not think we need HTTPS, though it does not hurt. If anybody tries to > fool us with man-in-the-middle via HTTP we should detect that just fine with > broken signatures (given signatures are provided...). > > Appending .sign m

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Daniel Micay
> I do not think we need HTTPS, though it does not hurt. If anybody tries to > fool us with man-in-the-middle via HTTP we should detect that just fine with > broken signatures (given signatures are provided...). Well, I mean when no signatures are available. It's not really that common for upstrea

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Christian Hesse
Daniel Micay on Mon, 2015/01/05 04:01: > On 04/01/15 05:03 PM, Doug Newgard wrote: > > On Sun, 4 Jan 2015 22:05:21 +0100 > > Christian Hesse wrote: > > > >> Hello everybody, > >> > >> pacman 4.2.0 gained support for verifying source tarballs with > >> kernel.org style signature. Some (even essen

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Daniel Micay
On 04/01/15 04:05 PM, Christian Hesse wrote: > Hello everybody, > > pacman 4.2.0 gained support for verifying source tarballs with kernel.org > style signature. Some (even essential) packages could benefit from that, > linux and git come to mind. > > How to handle this? Report a bug for every pac

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-05 Thread Daniel Micay
On 04/01/15 05:03 PM, Doug Newgard wrote: > On Sun, 4 Jan 2015 22:05:21 +0100 > Christian Hesse wrote: > >> Hello everybody, >> >> pacman 4.2.0 gained support for verifying source tarballs with >> kernel.org style signature. Some (even essential) packages could >> benefit from that, linux and git

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-04 Thread Christian Hesse
Doug Newgard on Sun, 2015/01/04 16:03: > On Sun, 4 Jan 2015 22:05:21 +0100 > Christian Hesse wrote: > > > Hello everybody, > > > > pacman 4.2.0 gained support for verifying source tarballs with > > kernel.org style signature. Some (even essential) packages could > > benefit from that, linux and

Re: [arch-general] gpg source validation for kernel.org style signatures

2015-01-04 Thread Doug Newgard
On Sun, 4 Jan 2015 22:05:21 +0100 Christian Hesse wrote: > Hello everybody, > > pacman 4.2.0 gained support for verifying source tarballs with > kernel.org style signature. Some (even essential) packages could > benefit from that, linux and git come to mind. > > How to handle this? Report a bug

[arch-general] gpg source validation for kernel.org style signatures

2015-01-04 Thread Christian Hesse
Hello everybody, pacman 4.2.0 gained support for verifying source tarballs with kernel.org style signature. Some (even essential) packages could benefit from that, linux and git come to mind. How to handle this? Report a bug for every package? Provide a list here? -- main(a){char*c=/*Schoene