Re: Secrecy and user trust
- From: Kevin Fenzi <kevin@xxxxxxxxx>
- Date: Wed, 3 Sep 2008 09:42:22 -0600
On Wed, 03 Sep 2008 10:30:39 -0400
davidsen@xxxxxxx (Bill Davidsen) wrote:
Anders Karlsson wrote:
* Travis Arnold <vestwearingpunk@xxxxxxxxx> [20080902 22:52]:Distributing that will be quite slow, since they need to (a)
[drivel snipped]
Hey I am currently downloading the ISO dvd to install after I
finish my day's lessons, is this not a good idea to do?
The word from the Fedora folks on Aug 14th was - don't update until
further notice. Since then, they have - IIRC - said it's safe to do
so. The ISO's should be safe, as well as the packages that you can
update to from the servers.
New updates should start rolling once they have resigned everything.
validate, then (b) sign, then (c) distribute out-of-band to mirrors,
Well, depends on what you mean by quite slow, but yes, doing all the
re-signing is taking a while right now. Distribution to mirrors will be
the next bottleneck.
and then hardest of all find a secure way to provide the public part
of the signing key. Obviously you don't risk letting someone slip in
a bogus NEW fake key and go around on this again.
Indeed.
The proposed plan (that has since had a few modifications):
http://lists.fedoraproject.org/pipermail/rel-eng/2008-August/001627.html
Suggestion: since the livna key is still secure (AFAIK) let them
distribute the new Fedora key and sign the RPM.
That was suggested before, but it's not a great solution for several
reasons: Not everyone has livna enabled. Having one repo publish keys
for another seems wrong, especially when they are not officially
connected.
kevin
Attachment:
signature.asc
Description: PGP signature
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines
- Follow-Ups:
- Re: Secrecy and user trust
- From: Tim
- Re: Secrecy and user trust
- From: Todd Zullinger
- Re: Secrecy and user trust
- References:
- Secrecy and user trust
- From: Bill Davidsen
- Re: Secrecy and user trust
- From: Bill Crawford
- Re: Secrecy and user trust
- From: Les Mikesell
- Re: Secrecy and user trust
- From: Bill Crawford
- Re: Secrecy and user trust
- From: Bill Davidsen
- Re: Secrecy and user trust
- From: John Aldrich
- Re: Secrecy and user trust
- From: Travis Arnold
- Re: Secrecy and user trust
- From: Anders Karlsson
- Re: Secrecy and user trust
- From: Bill Davidsen
- Secrecy and user trust
- Prev by Date: Re: NetworkManager and special routing [not solved]
- Next by Date: Re: Ello, I'm sort of new to the lists...is it best to install from livecd?
- Previous by thread: Re: Secrecy and user trust
- Next by thread: Re: Secrecy and user trust
- Index(es):
Relevant Pages
|