On Wed, Nov 23, 2005 at 04:37:05PM -0200, Henrique de Moraes Holschuh wrote:
> On Thu, 24 Nov 2005, Anthony Towns wrote:
> > Personally, I think it's cryptographic snake oil, at least in so far
> A signed deb has a seal of procedence and allows one to track the path it
> made through the system, and who changed it.  

That's what the .changes file is for.

> > > something that provides DD-to-user package signatures at least in some
> > > cases is very desirable indeed.
> > debian-devel-changes provides this.
> Not in a very useable form, and only for Debian packages uploaded to the
> official Debian archive.  This is hardly good enough.

Uh, packages not uploaded to the official Debian archive can do whatever
they want.


Attachment: signature.asc
Description: Digital signature

Reply via email to