Re: Remote signing of large files



On Sun, Dec 07, 2008 at 11:10:29AM +0000, Magnus Therning wrote:
Douglas A. Tutty wrote:
On Thu, Dec 04, 2008 at 12:26:31PM +0000, Magnus Therning wrote:

I wonder about the latest comment on this thread. Examine why you don't
want the secret key on the build server and why you would feel more
secure with the signing done on a separate server.

Well, the main reason is that there are _a_lot_ of people with direct
access to the build server. The idea is to find a way to limit people's
_direct_ access to the server with the keys. I know there are problems,
but hopefully it doesn't require too much work to at least achieve some
traceability in such a setup.

However, if people you don't totally trust have access to the build
server, couldn't they fitz the packages before they're signed?

Don't the keys have a passphrase option? Then, when you are ready to
sign the packages, you'd have to enter the passphrase.

Doug.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • RE: SBS SHared Printer Problem
    ... Does this issue happen for all the client workstations? ... If you try printing on the SBS server, ... Clear the registry keys and the driver on both the server and the client ... Microsoft Shared Fax Monitor ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS SHared Printer Problem
    ... They are shared from the server. ... please right click following registry keys and click ... Microsoft Shared Fax Monitor ... Install the latest driver for the printer and check if the issue ...
    (microsoft.public.windows.server.sbs)
  • Re: Serveur with encrypted partition : 2 steps boot.
    ... get the keys to decrypt and mount the encrypted partitions. ... server with the encrypted disks contact a different server that I ... Have it pull the keys for the partition from there. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: uniqid() function
    ... value if the PHP script is on only one server? ... Why do you not use the autoincrement featuer of the Database? ... - In these times you might need to actually create the data structure ... So you generate all the keys outside your server ...
    (comp.lang.php)
  • Re: OpenVMS SSH to freeSSHd on Windows
    ... I believe that freeSSHd used OpenSSH as a protpcol base and uses RSA ... authenticate to the server without a password. ... authenticate with public keys. ... During a connection event, ...
    (comp.os.vms)