[Gllug] Signitures on debs

Thom May thom at positive-internet.com
Thu Aug 8 09:42:42 UTC 2002


* Nix (nix at esperi.demon.co.uk) wrote :
> On Tue, 6 Aug 2002, Thom May moaned:
> > Debs themselves are not signed
> 
> Well, they *could* be. debsigs and debsig-verify are there for a
> reason...
> 

They were introduced by progeny for their distribution. Unfortunately the
necessary infrastructure hasn't been included into debian proper yet. 
(There is a patch to dpkg to do verification)

> > repository itself to sign the Release files, so you can ensure that the
> > mirror is not trojaned.
> > http://www.advogato.org/person/ajt/diary.html?start=12
> > (AJ is debian release manager ;-) )
> 
> I think he's offered the crown to anyone else mad enough to take it
> now Woody's out. I don't know if anyone has *been* that mad.
>
yeah, he's in a "i'm happy to do it, but if any one thinks they can do it
better, you're welcome to it" place. 
He's worked damn hard on the release process, so we (says thom, wearing his
debian developer's hat) should be able to push out releases on schedule...
Cheers,
-Thom

-- 
Gllug mailing list  -  Gllug at linux.co.uk
http://list.ftech.net/mailman/listinfo/gllug




More information about the GLLUG mailing list