Re: tl26 pretest start

Norbert Preining <[email protected]> Tue, 24 Feb 2026 00:24:42 +0100
Newsgroups gmane.comp.tex.live
Message-ID <aZzhuv0BR5Jq-tbo@burischnitzel>
On Mon, 23 Feb 2026, Max Chernoff wrote:
> It's a little tricky to tell because the email that Norbert was replying
> to was originally sent off-list, but I _think_ that the original

Really? I don't think so, it was in my spam folder, though. 
Message-ID: <trinity-7489d15e-8056-41a1-8507-2f7b71cbb762-1771258142126@trinity-msg-rest-gmx-gmx-live-7dfc9dcb89-45sss>

> suggestion was for TL to move away from GPG for verifying packages.

Yes, the suggestion was signify.

> Then from what I can tell, everyone agrees that there are other tools
> that can handle creating/verifying signatures, but people disagree on

Yes, that is without doubt ;-)

> whether these alternate tools can appropriately handle key distribution.

And trust, and verification of a key, etc etc etc.
Unfortunately there is a lot of bashing and FUD out there on gpg, but
all the alternatives that are presented, and that in most cases have a
far better architecture, command line, quality than gpg, lack the basic
principle of web of trust, nor do they have certification authorities
(besides sigstore).

Anyway, late it is. Good night

Norbert

--
DI Dr Norbert Preining                        https://www.preining.info
arXiv / Cornell University   +   IFMGA Guide   +   TU Wien  +  TeX Live
GPG: 0x860CDC13   fp: F7D8 A928 26E3 16A1 9FA0 ACF0 6CAC A448 860C DC13