if offloading is done for isos: ship the master key with qubes and
 provide a convenience command to the user. this command should
download (e.g. via torrent) and verify the image (a step the user
can'd do wrong anymore). this command could spawn a dispvm,
install torrent software, load the torrent and copy it to dom0.
from there the user could qvm-copy it to the vm with the install
medium.


This is a different proposal, and it would be a much larger
undertaking. It's certainly not something that the core Qubes devs
have time to do, so it would have to be a community-developed feature.
Would you like to take this project on?

my current idea:
 1) create a temporary download vm A
 2) use wget to get the signature + iso + release signing key

 4) create a temporary verify vm B
 5) copy the data from A to B
 6) destroy A

 7) copy the qubes-master key from dom0 to B
 4) set the master key to ultimate trust
 5) verify the release signing key
 6) check the signature
 7) copy the image to dom0
 8) destroy B

you also could do all steps in one vm.

i think this should be possible with the current tools. (i would have to look up how to do all this key management stuff via shell.

i have not this much time (and am not really skilled), but what i thought about would not be that much work.
if this solution is acceptable, i can give it a try.
it would be in form of some bash scripts.

maybe you could get other official repos to add them, too.
(debian (+ubuntu), fedora and arch should reach a significant
portion of the linux users)

Another interesting idea. I've never heard of a distro adding a
different OS's ISO as a package of their own, though.

asking can't hurt.


Well... why don't you ask them, then? :)

some random guy is more likely to be ignored than people officially connected to a project (but i could try to ask them and link them to this thread.)


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7cb32011-da34-b4a0-e9cb-e7942a6fa308%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to