Re: tl26 pretest start

Robert Alessi <[email protected]> Tue, 24 Feb 2026 09:08:38 +0100
Newsgroups gmane.comp.tex.live
Message-ID <[email protected]>
Hi Max, Norbert, Karl and others,

Very interesting.

And I'm the one who should apologize because I'm the one who came up
with this idea of signify. ( Actually, I had just happened to switch
from gpg to signify for OpenBSD, this is why, bad timing.)

Sorry,

-- Robert

On Tue, Feb 24, 2026 at 12:51:40AM +0100, Norbert Preining wrote:
> Hi Max,
> 
> > Well, that would only ever be required to verify the installer itself,
> > since after then, the public key would be verified, so we could use it
> > to sign everything else.
> 
> That is a different discussion - albeit an interesting idea:
> - get whatever key from tug.org (could be signify)
> - use that to verify the installer
> - use that to verify the downloaded tlpdb shasum (that is necessary,
>   the installer package alone is not useful to be signed)
> - one of the packages provides the key itself, too (I guess we need
>   that for updates?
> - install as usual
> 
> - tlmgr update uses the same key
> 
> That would allow switching to something else, agreed.
> And would have the advantage that we could embed the actual key into
> tlmgr itself, too.
> 
> Maybe for TL2027. Sounds like a nice project.