From mboxrd@z Thu Jan 1 00:00:00 1970 From: Joanna Rutkowska Subject: Re: pvops0 git tree signing? Date: Tue, 08 Jun 2010 15:43:17 +0200 Message-ID: <4C0E48F5.8060307@invisiblethingslab.com> References: <4C0E2EE7.8000305@invisiblethingslab.com> <20100608133719.GC4775@phenom.dumpdata.com> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1953296293==" Return-path: In-Reply-To: <20100608133719.GC4775@phenom.dumpdata.com> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xensource.com Errors-To: xen-devel-bounces@lists.xensource.com To: Konrad Rzeszutek Wilk Cc: "xen-devel@lists.xensource.com" List-Id: xen-devel@lists.xenproject.org This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --===============1953296293== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig8C9A65DCE481A6AA729CECC6" This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig8C9A65DCE481A6AA729CECC6 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On 06/08/2010 03:37 PM, Konrad Rzeszutek Wilk wrote: > On Tue, Jun 08, 2010 at 01:52:07PM +0200, Joanna Rutkowska wrote: >> So, any plans to start signing the pvops kernel commits? I'm really >> reluctant to build and sign, and then distribute, an RPM with the >> sources fetched from this repo, if I cannot verify they are authentic = in >> any way. I can easily imagine packagers from other distributions would= >> think similar. >> >> It's really just a matter of signing Jeremy's key with the "Xen.org >> master key" (0x79BAD9D8), and then typing git tag -s after every major= >> commit, no? >=20 > I don't know whether we are truly at a release stage yet? (there are > still tons of bugs). Or were you thinking more in terms of whenever > Jeremy merges Greg KH's stable 2.6.32 and then tag it? >=20 Yeah, whenever there is some bigger commit/merge, it would make sense to sign it. joanna. --------------enig8C9A65DCE481A6AA729CECC6 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAkwOSPUACgkQORdkotfEW87Q6QCghlfqhrXTiGi5mtlB88IVJwsh WH8AnigpS29UsGDASK04PZJwf+p0fwJ9 =YLrq -----END PGP SIGNATURE----- --------------enig8C9A65DCE481A6AA729CECC6-- --===============1953296293== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Xen-devel mailing list Xen-devel@lists.xensource.com http://lists.xensource.com/xen-devel --===============1953296293==--