Re: [arch-general] Archlinux ISO signing

2013-07-22 Thread Leonid Isaev
On Mon, 22 Jul 2013 08:13:23 +0900 Gaetan Bisson wrote: > [2013-07-21 18:56:28 -0400] Leonid Isaev: > > Is there a particular reason why the images themselves are signed > > as opposed to only their checksum files? For instance, Fedora provides > > sha256sums with inline sigs [1], and verifyi

Re: [arch-general] Archlinux ISO signing

2013-07-21 Thread Gaetan Bisson
[2013-07-21 18:56:28 -0400] Leonid Isaev: > Is there a particular reason why the images themselves are signed as > opposed to only their checksum files? For instance, Fedora provides > sha256sums with inline sigs [1], and verifying image checksum + checksum file > signature is _much_ less CPU

[arch-general] Archlinux ISO signing

2013-07-21 Thread Leonid Isaev
Hi, One of the ways to verify an archlinux iso image is via its gpg signature. However, doing this on an atom/geode system with < 1GiB of RAM is definitely not fun. And I suppose it also takes noticeable time to sign, even on an opteron/xeon server. Is there a particular reason why