Re: Verification of installed packages (was Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests))

2015-07-17 Thread Kent Fredric
On 17 July 2015 at 22:34, Andrew Savchenko wrote: > 2. Add an optional feature to emerge (or even to PMS?) allowing user > to provide a usable GPG key for signing packages CONTENTS files > after its generation. In order for such key to be usable during > emerge run, gpg-agent should be used; alter

Verification of installed packages (was Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests))

2015-07-17 Thread Andrew Savchenko
Hi, On Fri, 17 Jul 2015 10:18:14 +0200 Kristian Fiskerstrand wrote: > > Additionally, I feel that a signature is a means of acknowledging > > that a package has been looked over, and that developer has stated > > that they approve of the existing state. I'm not sure if others > > agree with that

Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests)

2015-07-17 Thread Kristian Fiskerstrand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 07/17/2015 11:48 AM, hasufell wrote: > On 07/17/2015 10:18 AM, Kristian Fiskerstrand wrote: >> On 07/17/2015 03:13 AM, NP-Hardass wrote: >> >>> Additionally, I feel that a signature is a means of >>> acknowledging that a package has been looked o

Re: OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests)

2015-07-17 Thread hasufell
On 07/17/2015 10:18 AM, Kristian Fiskerstrand wrote: > On 07/17/2015 03:13 AM, NP-Hardass wrote: > >> Additionally, I feel that a signature is a means of acknowledging >> that a package has been looked over, and that developer has stated >> that they approve of the existing state. I'm not sure if

OpenPGP verification (was Re: [gentoo-dev] Git, GPG Signing, and Manifests)

2015-07-17 Thread Kristian Fiskerstrand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 07/17/2015 03:13 AM, NP-Hardass wrote: > Additionally, I feel that a signature is a means of acknowledging > that a package has been looked over, and that developer has stated > that they approve of the existing state. I'm not sure if others > a