Re: catalog signature

"Bastian Eicher" <[email protected]>
Newsgroups gmane.comp.file-systems.zero-install.devel
Message-ID <[email protected]>
Hi Yosif,

Zero Install automatically trusts keys that are known by the key server. You
can get your key added there once you have published a public feed by
announcing it on the mailing list.

If a key used to sign a feed is not known by the key server Zero Install
asks the user whether to trust the key or not. However, for catalogs Zero
Install currently does not display this question. This may change in a
future version.

If you run a feed from the same location signed with the same key as the
catalog and answer the trust question with "Yes" Zero Install will remember
this and also trust the key for the catalog.

You can change the default key server in the "Advanced" tab of the
configuration window. To run your own key server you need to host this
Python application: https://github.com/0install/keylookup

Regards
Bastian


-----Original Message-----
From: Yosif Chumpov [mailto:[email protected]] 
Sent: Dienstag, 12. Mai 2015 15:04
To: Bastian Eicher
Subject: RE: c# dll feed creation

Hi Bastian,

the issue with "Unable to download GnuPG key file for .....some address... "
was caused by IIS. 
I just add MIME type for the gpg files and gpg can be downloaded now.

But my test catalog(with only one key) is not accepted by ZeroInstall again.
This time message is:
The feed "....." was not signed with any trusted key.

Note: I use the same key for both catalog and feed. 

Regards,
Yosif


-----Original Message-----
From: Bastian Eicher [mailto:[email protected]] 
Sent: Tuesday, May 12, 2015 12:36 PM
To: Yosif Chumpov
Cc: ''The Zero Install system''
Subject: RE: c# dll feed creation

Hi Yosif,

Zero Install always looks for GnuPG key files in the same directory the feed
or catalog is located in.
If you have created a signed feed with the Publishing Tools you can simply
upload the .xml, .xsl, .css and .gpg files together to the same directory on
your webserver.

The catalog files used in the main window of Zero Install also need to be
signed just like feeds.
Again you need to upload the .xml, .xsl, .css and .gpg files to the same
directory.

There are two ways to create signed catalogs:

Using the Publishing Tools:
0launch --command=0publish http://0install.de/feeds/ZeroInstall_Tools.xml
--xmlsign --catalog=mycatalog.xml C:\directory\with\feeds
C:\another_feed.xml

Using 0repo (a bit more complicated, since this also changes how you sign
feeds):
https://github.com/0install/0repo/

Regards,
Bastian


-----Original Message-----
From: Yosif Chumpov [mailto:[email protected]]
Sent: Dienstag, 12. Mai 2015 09:39
To: Bastian Eicher
Subject: RE: c# dll feed creation

Thanks for your help Bastian.

Please feel free to forward our mails to the Zero Install mailing list.

Today I'm trying to run some basic test on the remote machine via
ZeroInstall but when I add my own catalog I receive next error message: 

"Unable to download GnuPG key file for .....some address... "

Could you tell me how to define my own key serve?

Regards,
Yosif


------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.