Hello, Am Wed, Mar 29, 2023 at 01:49:23AM +0530 schrieb Vijaya Anand: > In the case of accessing Guix substitutes from p2p > network, we ensure authorization by Guix team by making sure the urn of the > substitute is the urn mentioned in the narinfo
no, currently substitutes are authenticated by a digital signature with one of the substitute servers (the user has control over which signing keys are accepted, see /etc/guix/acl). It happens after the download. And see https://guix.gnu.org/en/manual/devel/en/guix.html#Substitute-Server-Authorization . Andreas