On Fri, Jan 31, 2020 at 12:32:06PM +0100, Johnny Billquist wrote:
> Of course you can. But then you need to have a whole list of trusted public
> keys that needs to be managed, which again leads to the question of which
> keys are now the acceptable ones. And how to you trust new builders? Can
> anyone then be added to the list of official builders of packages, or how to
> you manage that side?
> Key management is not trivial.

Of course it's not. But this is not really a technical issue.

-- 
Manuel Bouyer <[email protected]>
     NetBSD: 26 ans d'experience feront toujours la difference
--

Reply via email to