Re: F45 Change Proposal: Sequoia opengpgverify (self-contained)
Björn Persson <[email protected]> Wed, 22 Jul 2026 20:11:56 +0200
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <[email protected]> |
Jakub Jelen wrote: > and sequoia's handling of multiple armored signatures in one file Bitcoin Core does that. Multiple people sign each release, so security isn't dependent on a single trusted entity. An attacker would have to acquire several people's signing keys. It's a good practice that should be encouraged. I had hoped that the package could be fixed some day to do meaningful signature verification. That will be harder if the ability to handle such files will be lost. Björn Persson -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE52SginNFTPmg+iBb4Tha3NZK5j8FAmphB+0ACgkQ4Tha3NZK 5j8yVg//adk+Jt3Z8A8r6Pqzec1mReXY/Er9mQWMYbvK7BIx+4VjmGVI7MJs0U6M v1cTW8FqoJzsn2+NHnthJHOWn3HHZ8ue2oZVv9PhoWX1XWvz1Iqa/hGyQIxh9iTA u4YKCLLAFskIgq1l/gulvEUy73LQMa7haqbJ+1Xm4iym9oMnetg7k2ui4AuPXNdD AL5EgzeTHhrWY4cY/qnUyItC6mJT/6ncsdA+m4FKYJ9D3MDKCFTZXx4n3X3Tw//Y zj83bPM0S6qSfUilYfsNHeU4iLrs9FVK6/ZzHP3KNcPbqqMbZWeu0JuGms/UpKxf H5W6y9Zz01iKVRlzsaa9hvE6DcivB8RU3h3og+W5EcH+7CHvl2PU9g2DUxH1RRz/ 4lQuGdxdn4mgYu0CEIwl0Bn2RdmNtxBcsTi2l3XPFZqeGe2WP1aMdyTOxnEQGKiD Gle0kR7WFeDairFWFDNMmK8jXs44bmpEK5h4hO6sw/uZUGZT9nlwU+0EZksiXRZe HlAYUYlexNsoYLyboqorkzNk7tS5SWRqzqO5XaK3H7HNYhMk/rBJ+gogjTlySiW/ wnJ9Uww8vuuG3Gos0jdEmz+zxUKRAHU5rksQnsLac5nEg1jFPwu/Wgm4oxzLNpge NMJ6NueSHem/ehYUNUDIZQhpP0HdcI8YlT03HXH/35L1BVVxaFs= =OJ+u -----END PGP SIGNATURE-----