Re: GPG Signatures for Installers
Wichert Akkerman <[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.installers |
|---|---|
| Organization | Simplon |
| Message-ID | <[email protected]> |
On 10/27/08 5:47 AM, Steve McMahon wrote: >> Small problem: we have no good trust path to generate and distribute such a >> key. >> > > Given the limited number of folks we need to coordinate, I think we > can manage it. > > You, Sidnei and I could exchange public keys. I think Limi or Geir > would recognize all our voices, and could be used to verify public-key > fingerprints by voice contact. You could generate a keypair and send > it to Sidnei and I encrypted against public keys, signed with yours. > > It's an awkward procedure, but our group of installer creators is > small and stable. > Voice contact is incredibly secure. I refuse to sign keys unless I have a face and a photo ID in front of me. Even though we have a need here that is no excuse to become sloppy about signatures. Wichert. -- Wichert Akkerman<[email protected]> It is simple to make things. http://www.wiggy.net/ It is hard to make things simple. ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ Plone-installers mailing list Plone-installers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-installers