From mboxrd@z Thu Jan 1 00:00:00 1970 From: Christian Rebischke Subject: Re: signed tarballs Date: Thu, 13 Apr 2017 22:28:12 +0200 Message-ID: <20170413202811.GA18419@motoko> References: <20170406233134.GA32113@motoko> <3197080.UOV2hoHuAT@x2> <20170411104403.GB386@motoko> <1591540.lCI4k97X9x@x2> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============3969500360874396442==" Return-path: Received: from mx1.redhat.com (ext-mx05.extmail.prod.ext.phx2.redhat.com [10.5.110.29]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 8579517177 for ; Thu, 13 Apr 2017 20:28:24 +0000 (UTC) Received: from mout02.posteo.de (mout02.posteo.de [185.67.36.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id ACA9731B338 for ; Thu, 13 Apr 2017 20:28:22 +0000 (UTC) In-Reply-To: <1591540.lCI4k97X9x@x2> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============3969500360874396442== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="45Z9DzgjV8m4Oswq" Content-Disposition: inline --45Z9DzgjV8m4Oswq Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Apr 11, 2017 at 10:03:54AM -0400, Steve Grubb wrote: > I added a sha256sum to the release announcement yesterday. You can also a= ccess=20 > the people page via https. >=20 Thanks, but as I stated before. SHA256 and https doesn't ensure a non-malicious tarball. Only a signed tarball can achieve this. --45Z9DzgjV8m4Oswq Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEba97gI+d8lE5YgAA0hRh49/iBg0FAljv31sACgkQ0hRh49/i Bg0BhRAAlP3L47wmlOfCo1uGR3H9Kyk8vl6G2GlyBG8A3KnJ7w3TKhA9lHXCamAx b9mb1sUs6fwmIca1W8rTbk0ztW64ctppOy4Aruq+eNH3MvLxzmGQUXGU1AIxOScA zfm800HNtwynDuLk1xuuLtgKXEcKNwJO2GXWDM5WARn18c7Bbi8un6DHLtUAYJfl 8Q4idbwGY0NWhtPz6FMBKHlLJ3Y9fRP+j8LL0qtHHqGQCcICOmmLAfYp93/wEDX2 YpzXKTEFl/ArFEUDmCRhuqhcxfG4l3RkiyT0B1Qe0XBoiVsNrRvuTuSERZztKmNp Sy/Uj4bu5vvS9Rn7drKQnggXzeEDqNdO45poG6ye3CpJuOs22ooleFzOuXsbRZHX ePdS4ElbsBU+YKDUkBnUhXlz/vOFj/oHGTrPvEIUm50onVzrbw5zEV6FshTwnVrQ jXIbF6kEESfh0+7V5NsUvzV3DIE9CxrCTKWw9bRXqpYESHKFlCsDUA3Cj0ta/tvn Pqi0TX6qJcGWvDMCIG76H8G8BAGItFaO2fZYK2vcAC2f8zmvpEjdPBv2MUhx5sQH H5j9y2vTu8AcZhSfRuKEcekNFRJQQt//XciP9hypii+XIgvAH/Y/hSjc45u9dQP9 VvHvf8iErKDhN+ViXb0U0BHP5iDZ79b6QhbaEVlLWcaEzqU92zs= =lX7l -----END PGP SIGNATURE----- --45Z9DzgjV8m4Oswq-- --===============3969500360874396442== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3969500360874396442==--