Re: catalog signature
"Bastian Eicher" <[email protected]>
| Newsgroups | gmane.comp.file-systems.zero-install.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Yosif, Zero Install automatically trusts keys that are known by the key server. You can get your key added there once you have published a public feed by announcing it on the mailing list. If a key used to sign a feed is not known by the key server Zero Install asks the user whether to trust the key or not. However, for catalogs Zero Install currently does not display this question. This may change in a future version. If you run a feed from the same location signed with the same key as the catalog and answer the trust question with "Yes" Zero Install will remember this and also trust the key for the catalog. You can change the default key server in the "Advanced" tab of the configuration window. To run your own key server you need to host this Python application: https://github.com/0install/keylookup Regards Bastian -----Original Message----- From: Yosif Chumpov [mailto:[email protected]] Sent: Dienstag, 12. Mai 2015 15:04 To: Bastian Eicher Subject: RE: c# dll feed creation Hi Bastian, the issue with "Unable to download GnuPG key file for .....some address... " was caused by IIS. I just add MIME type for the gpg files and gpg can be downloaded now. But my test catalog(with only one key) is not accepted by ZeroInstall again. This time message is: The feed "....." was not signed with any trusted key. Note: I use the same key for both catalog and feed. Regards, Yosif -----Original Message----- From: Bastian Eicher [mailto:[email protected]] Sent: Tuesday, May 12, 2015 12:36 PM To: Yosif Chumpov Cc: ''The Zero Install system'' Subject: RE: c# dll feed creation Hi Yosif, Zero Install always looks for GnuPG key files in the same directory the feed or catalog is located in. If you have created a signed feed with the Publishing Tools you can simply upload the .xml, .xsl, .css and .gpg files together to the same directory on your webserver. The catalog files used in the main window of Zero Install also need to be signed just like feeds. Again you need to upload the .xml, .xsl, .css and .gpg files to the same directory. There are two ways to create signed catalogs: Using the Publishing Tools: 0launch --command=0publish http://0install.de/feeds/ZeroInstall_Tools.xml --xmlsign --catalog=mycatalog.xml C:\directory\with\feeds C:\another_feed.xml Using 0repo (a bit more complicated, since this also changes how you sign feeds): https://github.com/0install/0repo/ Regards, Bastian -----Original Message----- From: Yosif Chumpov [mailto:[email protected]] Sent: Dienstag, 12. Mai 2015 09:39 To: Bastian Eicher Subject: RE: c# dll feed creation Thanks for your help Bastian. Please feel free to forward our mails to the Zero Install mailing list. Today I'm trying to run some basic test on the remote machine via ZeroInstall but when I add my own catalog I receive next error message: "Unable to download GnuPG key file for .....some address... " Could you tell me how to define my own key serve? Regards, Yosif ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y