On Wed, Nov 23, 2005 at 04:37:05PM -0200, Henrique de Moraes Holschuh wrote: > On Thu, 24 Nov 2005, Anthony Towns wrote: > > Personally, I think it's cryptographic snake oil, at least in so far > A signed deb has a seal of procedence and allows one to track the path it > made through the system, and who changed it.
That's what the .changes file is for. > > > something that provides DD-to-user package signatures at least in some > > > cases is very desirable indeed. > > debian-devel-changes provides this. > Not in a very useable form, and only for Debian packages uploaded to the > official Debian archive. This is hardly good enough. Uh, packages not uploaded to the official Debian archive can do whatever they want. Cheers, aj
signature.asc
Description: Digital signature