* Matthew Garrett: > I'm looking at implementing support for IMA file signatures inside > dpkg. The previous patches posted for this > (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850340) did so > using extended PAX metadata, but people didn't seem terribly > enthusiastic about that.
Do really want to have such a software singing infrastructure in Debian? What's the benefit to *our* users? (As opposed to commercial downstream distributions.)