On 15 May 2015 at 17:51, Michał Górny <mgo...@gentoo.org> wrote:
> Please note that the current syncing code does not verify the OpenPGP
> signature to confirm the authenticity of fetched snapshots and deltas.
> This feature will be added as soon as gentoo-keys support in Portage is
> available.

These are great news!
We can retire the webrsync.
Why not sign it similar to the portage snapshot are signed for now?
The webrsync signature validation is quite simple.

Just a reminder: please note the rollback prevention mechanism in
webrsync, it is not enough to check signature, but also prevent older
snapshot to be used.

Regards,
Alon

Reply via email to