From owner-freebsd-ports Mon Jan 1 9:58:48 2001 From owner-freebsd-ports@FreeBSD.ORG Mon Jan 1 09:58:46 2001 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from homer.softweyr.com (bsdconspiracy.net [208.187.122.220]) by hub.freebsd.org (Postfix) with ESMTP id 453C437B402; Mon, 1 Jan 2001 09:58:42 -0800 (PST) Received: from [127.0.0.1] (helo=softweyr.com ident=Fools trust ident!) by homer.softweyr.com with esmtp (Exim 3.16 #1) id 14D9Jo-0000AH-00; Mon, 01 Jan 2001 11:04:24 -0700 Sender: wes@FreeBSD.ORG Message-ID: <3A50C6A8.3E02FAE@softweyr.com> Date: Mon, 01 Jan 2001 11:04:24 -0700 From: Wes Peters Organization: Softweyr LLC X-Mailer: Mozilla 4.75 [en] (X11; U; Linux 2.2.12 i386) X-Accept-Language: en MIME-Version: 1.0 To: Mario Sergio Fujikawa Ferreira Cc: Kris Kennaway , "Michael C . Wu" , ports@FreeBSD.ORG, Robert Watson , Warner Losh Subject: Re: Package signing tools References: <3A4ED1C0.14061CE5@softweyr.com> <20001231003920.A24519@peorth.iteration.net> <3A4EDCA9.5CEA7114@softweyr.com> <20010101083459.B12422@citusc.usc.edu> <20010101143803.A3416@Fedaykin.here> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-ports@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Mario Sergio Fujikawa Ferreira wrote: > > On Mon, Jan 01, 2001 at 08:34:37AM -0800, Kris Kennaway wrote: > > On Sun, Dec 31, 2000 at 12:13:45AM -0700, Wes Peters wrote: > > > > > Yeah, it's a good idea, but this is really a simple standalone program. > > > It doesn't prevent you from pkg_add'ing something, you have to chose to > > > pkg_check it and see if the result is kosher. It is at this time orthogonal > > > to pkg_version. > > > > Checking the signature should be automatic and part of pkg_add, which > > should refuse to add the package if it fails. > > And, "smart users" should be allowed to bypass this if > they wish so. ;) > Just like checksum. But, with scarier warnings. Right. Should checking the signature be the default, with an option to skip it, or should it be optional to pkg_add? -- "Where am I, and what am I doing in this handbasket?" Wes Peters Softweyr LLC wes@softweyr.com http://softweyr.com/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ports" in the body of the message