* pvops0 git tree signing?
@ 2010-06-08 11:52 Joanna Rutkowska
2010-06-08 13:37 ` Konrad Rzeszutek Wilk
0 siblings, 1 reply; 3+ messages in thread
From: Joanna Rutkowska @ 2010-06-08 11:52 UTC (permalink / raw)
To: xen-devel@lists.xensource.com
[-- Attachment #1.1: Type: text/plain, Size: 476 bytes --]
So, any plans to start signing the pvops kernel commits? I'm really
reluctant to build and sign, and then distribute, an RPM with the
sources fetched from this repo, if I cannot verify they are authentic in
any way. I can easily imagine packagers from other distributions would
think similar.
It's really just a matter of signing Jeremy's key with the "Xen.org
master key" (0x79BAD9D8), and then typing git tag -s after every major
commit, no?
Thanks,
joanna.
[-- Attachment #1.2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 226 bytes --]
[-- Attachment #2: Type: text/plain, Size: 138 bytes --]
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xensource.com
http://lists.xensource.com/xen-devel
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: pvops0 git tree signing?
2010-06-08 11:52 pvops0 git tree signing? Joanna Rutkowska
@ 2010-06-08 13:37 ` Konrad Rzeszutek Wilk
2010-06-08 13:43 ` Joanna Rutkowska
0 siblings, 1 reply; 3+ messages in thread
From: Konrad Rzeszutek Wilk @ 2010-06-08 13:37 UTC (permalink / raw)
To: Joanna Rutkowska; +Cc: xen-devel@lists.xensource.com
On Tue, Jun 08, 2010 at 01:52:07PM +0200, Joanna Rutkowska wrote:
> So, any plans to start signing the pvops kernel commits? I'm really
> reluctant to build and sign, and then distribute, an RPM with the
> sources fetched from this repo, if I cannot verify they are authentic in
> any way. I can easily imagine packagers from other distributions would
> think similar.
>
> It's really just a matter of signing Jeremy's key with the "Xen.org
> master key" (0x79BAD9D8), and then typing git tag -s after every major
> commit, no?
I don't know whether we are truly at a release stage yet? (there are
still tons of bugs). Or were you thinking more in terms of whenever
Jeremy merges Greg KH's stable 2.6.32 and then tag it?
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: pvops0 git tree signing?
2010-06-08 13:37 ` Konrad Rzeszutek Wilk
@ 2010-06-08 13:43 ` Joanna Rutkowska
0 siblings, 0 replies; 3+ messages in thread
From: Joanna Rutkowska @ 2010-06-08 13:43 UTC (permalink / raw)
To: Konrad Rzeszutek Wilk; +Cc: xen-devel@lists.xensource.com
[-- Attachment #1.1: Type: text/plain, Size: 911 bytes --]
On 06/08/2010 03:37 PM, Konrad Rzeszutek Wilk wrote:
> On Tue, Jun 08, 2010 at 01:52:07PM +0200, Joanna Rutkowska wrote:
>> So, any plans to start signing the pvops kernel commits? I'm really
>> reluctant to build and sign, and then distribute, an RPM with the
>> sources fetched from this repo, if I cannot verify they are authentic in
>> any way. I can easily imagine packagers from other distributions would
>> think similar.
>>
>> It's really just a matter of signing Jeremy's key with the "Xen.org
>> master key" (0x79BAD9D8), and then typing git tag -s after every major
>> commit, no?
>
> I don't know whether we are truly at a release stage yet? (there are
> still tons of bugs). Or were you thinking more in terms of whenever
> Jeremy merges Greg KH's stable 2.6.32 and then tag it?
>
Yeah, whenever there is some bigger commit/merge, it would make sense to
sign it.
joanna.
[-- Attachment #1.2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 226 bytes --]
[-- Attachment #2: Type: text/plain, Size: 138 bytes --]
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xensource.com
http://lists.xensource.com/xen-devel
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2010-06-08 13:43 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-08 11:52 pvops0 git tree signing? Joanna Rutkowska
2010-06-08 13:37 ` Konrad Rzeszutek Wilk
2010-06-08 13:43 ` Joanna Rutkowska
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).