Re: tl26 pretest start
Robert Alessi <[email protected]> Tue, 24 Feb 2026 09:08:38 +0100
| Newsgroups | gmane.comp.tex.live |
|---|---|
| Message-ID | <[email protected]> |
Hi Max, Norbert, Karl and others, Very interesting. And I'm the one who should apologize because I'm the one who came up with this idea of signify. ( Actually, I had just happened to switch from gpg to signify for OpenBSD, this is why, bad timing.) Sorry, -- Robert On Tue, Feb 24, 2026 at 12:51:40AM +0100, Norbert Preining wrote: > Hi Max, > > > Well, that would only ever be required to verify the installer itself, > > since after then, the public key would be verified, so we could use it > > to sign everything else. > > That is a different discussion - albeit an interesting idea: > - get whatever key from tug.org (could be signify) > - use that to verify the installer > - use that to verify the downloaded tlpdb shasum (that is necessary, > the installer package alone is not useful to be signed) > - one of the packages provides the key itself, too (I guess we need > that for updates? > - install as usual > > - tlmgr update uses the same key > > That would allow switching to something else, agreed. > And would have the advantage that we could embed the actual key into > tlmgr itself, too. > > Maybe for TL2027. Sounds like a nice project.