Mailing List Archive

Keys on a cd?
On Mon, 8 Nov 2004 10:19:27 +0100
Tobias Klausmann <klausman@schwarzvogel.de> wrote:

> Hi!
>
> On Mon, 08 Nov 2004, Kurt Lieber wrote:
Where can I get those?
>
> 0x012E7061
> 0x1E37DA76
> 0x2D86E6F4
> 0x3526BFED
> 0x8256272E
> 0x8F01B50A
> 0x96E7B687
> 0xAD8D10B6
> 0xAF09E289
> 0xB0FAE1C1
> 0xBC58B271
> 0xC4BBD87A
> 0xCA9EC979
> 0xE95F7581
> 0xEB0E2EF7

As per this. Would it be sensible, once the gpg system is up and running in portage. To have a cd, obtainable from the gentoo store, with all the current public keys on it.

Dev's could be asked to get updated keys to the cd's maintainers on a regular basis.

Obviously the keys should all be on public servers too, it would just be another way to get the keys.

The cd could be distributed along side all the installation cd's too.
Re: Keys on a cd? [ In reply to ]
On Mon, Nov 08, 2004 at 10:36:24AM +0000 or thereabouts, Anthony Metcalf wrote:
> As per this. Would it be sensible, once the gpg system is up and running in portage. To have a cd, obtainable from the gentoo store, with all the current public keys on it.

Not the way we've implemented GPG signing -- each dev has their own ebuild
signing key. Given the churn rate in the dev community, a CD would be out
of date almost instantly.

My $.02 and all that.

--kurt