Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 12 Jan 2000 07:55:28 +1100
From:      Peter Jeremy <peter.jeremy@alcatel.com.au>
To:        Kris Kennaway <kris@hub.freebsd.org>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: cvs commit: src/usr.sbin/ctm/ctm ctm.1 src/usr.sbin/ctm/ctm_rmail ctm_rmail.1
Message-ID:  <00Jan12.075529est.40330@border.alcanet.com.au>
In-Reply-To: <Pine.BSF.4.21.0001111148150.95142-100000@hub.freebsd.org>; from kris@hub.freebsd.org on Wed, Jan 12, 2000 at 06:45:14AM %2B1100
References:  <200001111218.WAA31198@nymph.detir.qld.gov.au> <Pine.BSF.4.21.0001111148150.95142-100000@hub.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 2000-Jan-12 06:45:14 +1100, Kris Kennaway <kris@hub.freebsd.org> wrote:
> we need to get a FreeBSD certificate authority of some sort set
>up, and the CTM administrator would (have the generator) sign each delta
>with a DSA key, the public half of which is distributed to the clients.

Sounds excellent.  As a further check, it would be nice if someone
with access to the master CTM repository could run md5(1) across the
repository and make the result available (together with the CTM deltas
that it relates to).  This would let people check that their local
repositories haven't accumulated any bitrot.

BTW, in making these changes to the CTM format, remember to make sure
that the existing ctm can at least apply the new deltas (even if it
can't understand the signatures) :-).

Peter


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?00Jan12.075529est.40330>