From mboxrd@z Thu Jan 1 00:00:00 1970 From: Joanna Rutkowska Subject: Re: request to sign software Date: Tue, 30 Mar 2010 11:58:25 +0200 Message-ID: <4BB1CB41.5030305@invisiblethingslab.com> References: <4BAF2918.4040207@invisiblethingslab.com> <4BB0E7A8.10403@goop.org> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0786962609==" Return-path: In-Reply-To: <4BB0E7A8.10403@goop.org> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xensource.com Errors-To: xen-devel-bounces@lists.xensource.com To: Jeremy Fitzhardinge Cc: "xen-devel@lists.xensource.com" , Ian Jackson , Keir Fraser , Stephen Spector List-Id: xen-devel@lists.xenproject.org This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --===============0786962609== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig03DF37583FA4EA7E94B61CF6" This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig03DF37583FA4EA7E94B61CF6 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On 03/29/2010 07:47 PM, Jeremy Fitzhardinge wrote: > On 03/28/2010 03:02 AM, Joanna Rutkowska wrote: >> Just a rather obvious request that you digitally sign all the publishe= d >> tgz packages, as well as hg/git tags, so that it was possible to ensur= e >> that the software I download from xen.org (or fetch from Jeremy's GIT)= >> is authentic. This is especially important for those people who would >> like to build (and distribute!) their own products based on Xen. >> >> Hopefully you can start doing this with the upcoming 4.0.0 and 3.4.3 >> versions of Xen, and the "official" pvops kernels (hopefully there wil= l >> be some pvops commit tagged as "official"? I assume from >> xen/stale-2.6.32.x?) >> =20 >=20 > (I prefer to call it "stable", but I can see how one might get them > confused ;) >=20 Sorry, just noticed this. Wasn't intentional ;) j. --------------enig03DF37583FA4EA7E94B61CF6 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAkuxy0IACgkQORdkotfEW85aJwCgiDhb9QihLPFRsM5HMxUDQ1tZ ZDYAnRC2IX5cQZ9VqV/BiEFgJX+i9Utz =qDlE -----END PGP SIGNATURE----- --------------enig03DF37583FA4EA7E94B61CF6-- --===============0786962609== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Xen-devel mailing list Xen-devel@lists.xensource.com http://lists.xensource.com/xen-devel --===============0786962609==--