From owner-freebsd-security@freebsd.org Fri Nov 4 16:03:25 2016 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E3AF4C2FA59 for ; Fri, 4 Nov 2016 16:03:25 +0000 (UTC) (envelope-from org.freebsd.security@io7m.com) Received: from mail.io7m.com (io7m.com [159.203.63.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.io7m.com", Issuer "arc7 CA" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id C76AB321 for ; Fri, 4 Nov 2016 16:03:24 +0000 (UTC) (envelope-from org.freebsd.security@io7m.com) Received: from copperhead.int.arc7.info (cust187-dsl61.idnet.net [212.69.61.187]) by mail.io7m.com (Postfix) with ESMTPSA id 9226918A61B for ; Fri, 4 Nov 2016 16:03:17 +0000 (UTC) Date: Fri, 4 Nov 2016 16:03:04 +0000 From: org.freebsd.security@io7m.com To: freebsd-security@freebsd.org Subject: Signatures for base.txz, kernel.txz, etc? Message-ID: <20161104160304.7e3e9815@copperhead.int.arc7.info> Organization: io7m.com MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; boundary="Sig_/eTpBogXs=zRmAZDX3I0j2Rp"; protocol="application/pgp-signature" X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 04 Nov 2016 16:03:26 -0000 --Sig_/eTpBogXs=zRmAZDX3I0j2Rp Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Hello. Are there any plans to provide PGP signatures on base.txz, kernel.txz, and friends? Right now, the only (apparent) way to obtain them is via http://ftp.freebsd.org over unsecured HTTP (the HTTPS certificate is misconfigured; it's for download.freebsd.org) and no signature files are provided. Regards, Mark --Sig_/eTpBogXs=zRmAZDX3I0j2Rp Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iQIrBAEBCgAVBQJYHLE4DhxtYXJrQGlvN20uY29tAAoJEAKt2nV+RgR4WJEQAKdA +MKpE3J2YE5n0Ni/GopIOQAUhQ4XANfEyoWRl1CyUqCMoWnrrV0Rfk4KxddDOqem 9Sbx1JiR1CSZpNU3S1T4jfL06xhIIUpN9xbBWuxNzGqanixljcvXCfbGonB7l3ey 4uEg/MtU14hqETZQAX/KpzzA3DcYCnv8vMH8bAmhzcHz4AoMQwVRRlEKFQVyRT4y sTgP3OoP+i6sRCQTrd7k1kyFWvsWmL4a8plLYPDHfm22AwSVKQCCzz767UOt0yGq QmzX1p3/1iveHpv3O8tkSQKL2I0U1ZJA/u303P2j2FTW98jA+C/TQ1CGOl6mH0AI YGNxdG3VZ7DifHJCXmTyRIGW8VjQUr2s5ixM7JrS47b0HZxdfatZ+i5YvrBf2fui xDJvfaQfr2CXu5R5EK6l6vrXq+UgdqiSKDQ/nNHEwOQQuk8zRbVUcdCdCeY8yFta jlPrlpgfFd4dyq3kXYXtMiKPxDHyXYOmbv2wCWeYc1u5VravI2lCKX8mGf82PlLb mGkkKNY7II6ZeH93OMZp5baZ/uUppR0/UzUP+x1YEby0PsvzQMXVAmIJhK0aSf4Q kKeBtDX2oBfgNwkiThKt1upou7aBZ063ATJlo7SQShRJYrBNw3uHqgvLWn792YGJ JqQGri4EoBEM7AgT+3R0ye/638EzSCFfSO8KDOUy =5U+a -----END PGP SIGNATURE----- --Sig_/eTpBogXs=zRmAZDX3I0j2Rp--