Re: Portage rsync security
Matthias Geerdsen <[email protected]> Thu, 20 Mar 2008 14:46:53 +0100
| Newsgroups | gmane.linux.gentoo.security |
|---|---|
| Message-ID | <[email protected]> |
Robert Buchholz wrote on 03/20/2008 02:07 PM: > (CVS, core gentoo infra) and then check it on the user side. If you > want to do this right now, you can change your tree syncing to manually > download the gpg-signed portage-latest.tar.bz2 tree snapshots from your > local distfiles mirror and check them. emerge-webrsync can do the downloading for you. The current version in svn [1] should also be able to handle the verification, just note that the key id changed to 239C75C4 [2]. Regards, Matthias [1] <http://sources.gentoo.org/viewcvs.py/portage/main/trunk/bin/emerge-webrsync?view=markup> [2] <http://bugs.gentoo.org/show_bug.cgi?id=130039> -- Matthias Geerdsen (vorlon) Gentoo Linux Security Team http://security.gentoo.org
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFH4mrYGc/RGrFqUYMRAoZVAJ9980bWiw04HOvmdE5eLraPcZKYzACfSN1M 9HZAPBHD6w0VNkP4Kkln9uM= =jn/7 -----END PGP SIGNATURE-----