On 15 May 2015 at 17:51, Michał Górny <mgo...@gentoo.org> wrote: > Please note that the current syncing code does not verify the OpenPGP > signature to confirm the authenticity of fetched snapshots and deltas. > This feature will be added as soon as gentoo-keys support in Portage is > available.
These are great news! We can retire the webrsync. Why not sign it similar to the portage snapshot are signed for now? The webrsync signature validation is quite simple. Just a reminder: please note the rollback prevention mechanism in webrsync, it is not enough to check signature, but also prevent older snapshot to be used. Regards, Alon