Re: Mirror layout proposal
Amir Guindehi <[email protected]> Sat, 02 Aug 2003 14:51:01 +0200
| Newsgroups | gmane.linux.zynot.zynaut |
|---|---|
| Organization | DataCore GmbH |
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --===============74674872279190097== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig563415F20A294D4B3C192601" This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig563415F20A294D4B3C192601 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Hi, > * No comments on where gpg signatures should go - Security guys, we > actually need a whole new approach at this, not only for distfiles, > but also for build scripts. I always imagined that those signatures are kept within the ebuild directory. I would propose a sepparate file containing the signatures and using a file type extention of the for gna-1.0.ebuild.gpg or something along this line. This will allow us to use another files named gna-1.0.ebuild.XXX for different sorts of signatures, eg: x509. Naturally those signature files could also be placed to arbitrary different places. I'm not sure we would want this. Shouldn't ebuild and signatures share a common directory? > ... that have not been gpg signed by X number of trusted devs ... I would propose to implement this in an abstract way so that _different_ types of trust can be applied! I can imagine multiple form of trust as for example: GPG: - Trust in a keyring of Zynot developers - Trust in a top level signature of one or multiple Zynot GPG Certificate Authority Certificates, created specially for this purpose. This maps a hirarchical trust schema like the x509 schema to GPG. Trust would essentially be provided by giving the End-User a keyring of trusted GPG CA Certificates, and not individual developers. By defining apropriate certificate verification depths these special signature certificates could be checked. - Trust in a simple web of trust given by a arbitrary keyring (user supplied) x509: - Trust in the Zynot Certificate Authority's trust chain - Trust in a foreign Certificate Authority's trust chain Last but not lest: - Trust in any combination of the above. This will allow the checking of the GPG signatures by x509 signatures and vice versa. It will also allow to use a web of trust and hirarchical trust chain in combination giving the system a independency of arbitrary bugs in one or the other form of signatures and trust schemas... Please share your thoughts! - Amir -- Amir Guindehi, [email protected] DataCore GmbH, Witikonerstrasse 289, 8053 Zurich, Switzerland --------------enig563415F20A294D4B3C192601 Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2-nr1 (Windows 2000) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQE/K7O+bycOjskSVCwRAiCcAJsFquPsl7aq+AWEBTVFp+VN9jNW4ACfS/hb 07GG3PQU3+CSsIxAuQijVbc= =bTgQ -----END PGP SIGNATURE----- --------------enig563415F20A294D4B3C192601-- --===============74674872279190097== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zynaut mailing list [email protected] http://lists.zynot.org/mailman/listinfo/zynaut --===============74674872279190097==--