Re: pkgbase repo signing infrastructure
Sulev-Madis Silber <[email protected]> Sun, 30 Nov 2025 12:42:34 +0200
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Message-ID | <[email protected]> |
eh... i've always wanted to know how fbsd signs all things it releases. apparently it's kind of like i imagined. that would show i'm not bad at security i guess :p now i know, and that's very good! but to this day, i'm wondering how all that actually gets released. like what scripts actually create it all, releases, packages, etc. sync to mirrors, etc i don't mean things in release/ to this day i've seen only bits so what security officer thinks, can those be shared? supposedly they are in private repo(s), i heard and "not very interesting" i mean, if there are any _secrets_ in there, it would be about last time for those secrets be separated from tools so the rest could be shared. maybe that even helps finding bugs as amount of eyes increases a lot those things could be even documented. i mean after all fbsd handbook and manpages are already world class information sources for sysadmin knowledge. which i've read and praised since 2002 when i installed my first fbsd, a 4.6 anyway that was a very good readin about subject