Re: Package and image signatures

2008-07-19 Thread Jeff
On Thu, Jul 17, 2008 at 07:26:01AM +0200, Kalle Happonen wrote:
> Hi,
> would it be possible to add signatures for the packages and hashes for 
> the images?

As well, the prebuilt image files should have at least one of: md5sum,
sha1sum, or pgp signature files.

-- 
Jeff

My other computer is an abacus.


___
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community


Package and image signatures

2008-07-16 Thread Kalle Happonen
Hi,
would it be possible to add signatures for the packages and hashes for 
the images? The latter one should be easy and it could be pretty much 
automated in the build process. I agree that it doesn't help much, but 
it would stop some of possible malicious repo tampering. I'm not saying 
it will happen, but they got Ubuntu too so it's always a possibility :)..

Having package signatures is a bit more work, at least if you want to do 
it well and securely, but I think this would be importat at latest when 
openmoko starts getting mirrors, just to make sure users get correct 
versions of software.

Cheers,
Kalle

___
Openmoko community mailing list
community@lists.openmoko.org
http://lists.openmoko.org/mailman/listinfo/community