* Jordan Brown <[EMAIL PROTECTED]> [2008-05-29 22:34]:
> Sounds like might you need *three* domain names in there some place, in 
> the fully-qualified URL case:
> 
> - the name of the server you're retrieving from

  The mirrors property of the image's configuration for a particular
  authority contains the list of mirrors.  Use the HTTPS transport, if
  offered, to verify that this server is trusted.
 
> - the name of the organization that built and signed the package and so 
> is responsible for the binaries

  We verify this by having cryptographically signed catalogs and manifests.

> - the name of the organization that originally wrote the software and so 
> is responsible for the sources

> (Of course, that still doesn't take into account the possibility that 
> there are multiple levels of source authorship.)

  These are properties in the metadata, and were discussed in the "Tags
  and attributes" thread.

  - Stephen

-- 
[EMAIL PROTECTED]  http://blogs.sun.com/sch/
_______________________________________________
pkg-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/pkg-discuss

Reply via email to