if offloading is done for isos: ship the master key with qubes and
provide a convenience command to the user. this command should
download (e.g. via torrent) and verify the image (a step the user
can'd do wrong anymore). this command could spawn a dispvm,
install torrent software, load the torrent and copy it to dom0.
from there the user could qvm-copy it to the vm with the install
medium.
This is a different proposal, and it would be a much larger
undertaking. It's certainly not something that the core Qubes devs
have time to do, so it would have to be a community-developed feature.
Would you like to take this project on?
my current idea:
1) create a temporary download vm A
2) use wget to get the signature + iso + release signing key
4) create a temporary verify vm B
5) copy the data from A to B
6) destroy A
7) copy the qubes-master key from dom0 to B
4) set the master key to ultimate trust
5) verify the release signing key
6) check the signature
7) copy the image to dom0
8) destroy B
you also could do all steps in one vm.
i think this should be possible with the current tools. (i would have to
look up how to do all this key management stuff via shell.
i have not this much time (and am not really skilled), but what i
thought about would not be that much work.
if this solution is acceptable, i can give it a try.
it would be in form of some bash scripts.
maybe you could get other official repos to add them, too.
(debian (+ubuntu), fedora and arch should reach a significant
portion of the linux users)
Another interesting idea. I've never heard of a distro adding a
different OS's ISO as a package of their own, though.
asking can't hurt.
Well... why don't you ask them, then? :)
some random guy is more likely to be ignored than people officially
connected to a project (but i could try to ask them and link them to
this thread.)
--
You received this message because you are subscribed to the Google Groups
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/qubes-users/7cb32011-da34-b4a0-e9cb-e7942a6fa308%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.