From owner-freebsd-security@FreeBSD.ORG Wed Nov 30 00:04:10 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3A9AC16A41F; Wed, 30 Nov 2005 00:04:10 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from elvis.mu.org (elvis.mu.org [192.203.228.196]) by mx1.FreeBSD.org (Postfix) with ESMTP id BE6E443D96; Wed, 30 Nov 2005 00:03:45 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from obsecurity.dyndns.org (elvis.mu.org [192.203.228.196]) by elvis.mu.org (Postfix) with ESMTP id 544B31A4D83; Tue, 29 Nov 2005 16:03:27 -0800 (PST) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id B4CE6513A2; Tue, 29 Nov 2005 19:03:26 -0500 (EST) Date: Tue, 29 Nov 2005 19:03:26 -0500 From: Kris Kennaway To: Colin Percival Message-ID: <20051130000326.GA60924@xor.obsecurity.org> References: <20051129120151.5A2FB16A420@hub.freebsd.org> <002601c5f4fa$b5115320$e403000a@rickderringer> <20051129232703.GA60060@xor.obsecurity.org> <20051129233316.GA60287@xor.obsecurity.org> <438CE7EE.4010005@freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="C7zPtVaVf+AK4Oqc" Content-Disposition: inline In-Reply-To: <438CE7EE.4010005@freebsd.org> User-Agent: Mutt/1.4.2.1i Cc: freebsd-security@freebsd.org, aristeu , Kris Kennaway Subject: Re: Reflections on Trusting Trust X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Nov 2005 00:04:10 -0000 --C7zPtVaVf+AK4Oqc Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Nov 29, 2005 at 03:44:46PM -0800, Colin Percival wrote: > Kris Kennaway wrote: > > Also, pkg_sign(1) has existed for a long time, but needs the support > > infrastructure to make it usable. >=20 > Last I heard, pkg_sign(1) became non-functional when we changed from > gzipped tarballs to bzip2ed tarballs for packages. Yeah, that could well be true. Kris --C7zPtVaVf+AK4Oqc Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFDjOxOWry0BWjoQKURAhCwAKC6pWkMoicDvPB767nhB7n2P0wfJwCdFiYg cquZvIJAVj0kGQKSMubs7Xk= =H4jn -----END PGP SIGNATURE----- --C7zPtVaVf+AK4Oqc--