From owner-freebsd-stable Fri Mar 20 18:51:53 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id SAA02111 for freebsd-stable-outgoing; Fri, 20 Mar 1998 18:51:53 -0800 (PST) (envelope-from owner-freebsd-stable@FreeBSD.ORG) Received: from ns1.yes.no (ns1.yes.no [195.119.24.10]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id SAA02086 for ; Fri, 20 Mar 1998 18:51:40 -0800 (PST) (envelope-from eivind@bitbox.follo.net) Received: from bitbox.follo.net (bitbox.follo.net [194.198.43.36]) by ns1.yes.no (8.8.7/8.8.7) with ESMTP id CAA09867; Sat, 21 Mar 1998 02:51:22 GMT Received: (from eivind@localhost) by bitbox.follo.net (8.8.6/8.8.6) id DAA19003; Sat, 21 Mar 1998 03:51:20 +0100 (MET) Message-ID: <19980321035120.19492@follo.net> Date: Sat, 21 Mar 1998 03:51:20 +0100 From: Eivind Eklund To: Robert Watson , Derek Flowers Cc: Wes Peters - Softweyr LLC , "Daniel O'Callaghan" , stable@FreeBSD.ORG Subject: Re: after the release ... References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 0.89.1i In-Reply-To: ; from Robert Watson on Fri, Mar 20, 1998 at 09:33:35PM -0500 Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk On Fri, Mar 20, 1998 at 09:33:35PM -0500, Robert Watson wrote: > On Fri, 20 Mar 1998, Derek Flowers wrote: > > > Why not model it after RPM? If the size and md5 do not match, return an > > error. Allow the user to overide the check if they wish to do so. > > > > Just to get a feel for pkg_add, what are the stpes taken to add the > > software? I'm thinking the check could be done in the install script, > > assuming it executes a script like make would. > > Errr. How do you know that the md5 is right? Digital signatures have to > come into this somewhere :). Or secure trusted transmission (i.e., the > HTTPS idea). I'm right now looking at adding support for the JAR manifest standard to pkg_add. The only loss I can see is that until somebody re-write the signing software you'll have to have Java installed to sign packages. I hope the amount of work to make this work should be feasible to have it ready over the next few days - it looks fairly simple. More info is at http://www.javasoft.com/products/jdk/1.2/docs/guide/jar/manifest.html Eivind. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message