signing releases

2008-12-14 Thread Per Olofsson
Hi LyX developers, Have you thought about GPG-signing the LyX tarballs? As a Debian packager, it would make me feel a bit safer :-) -- Pelle [please cc me on replies]

Re: signing releases

2008-12-14 Thread Jean-Marc Lasgouttes
Have you thought about GPG-signing the LyX tarballs? As a Debian packager, it would make me feel a bit safer :-) Juergen, I think it would be an excellent idea. JMarc

Re: signing releases

2008-12-14 Thread Jürgen Spitzmüller
Jean-Marc Lasgouttes wrote: > > Have you thought about GPG-signing the LyX tarballs? As a Debian > > packager, it would make me feel a bit safer :-) > > Juergen, I think it would be an excellent idea. What is the correct procedure to do this? Jürgen

Re: signing releases

2008-12-15 Thread Jean-Marc Lasgouttes
Jürgen Spitzmüller writes: > Jean-Marc Lasgouttes wrote: >> > Have you thought about GPG-signing the LyX tarballs? As a Debian >> > packager, it would make me feel a bit safer :-) >> >> Juergen, I think it would be an excellent idea. > > What is the correct procedure to do this? It seems that the

Re: signing releases

2008-12-15 Thread Jürgen Spitzmüller
Jean-Marc Lasgouttes wrote: > I guess we would need one key for you and one for Jose (we cannot share > a LyX key). I have a key. But I guess it is not very authorative (due to missing counter- signs). And on the server, we would just upload the sig-Files matching the tarballs? Jürgen

Re: signing releases

2008-12-16 Thread Jürgen Spitzmüller
Per Olofsson wrote: > Of course, there are all sorts of security issues here involving key > distribution and the like, but the point is that it would still be > much more secure than the present situation. Establishing a trust-path > by getting your key signed would be an improvement, but it is no

Re: signing releases

2008-12-16 Thread Per Olofsson
Hi, Jürgen Spitzmüller wrote: > Jean-Marc Lasgouttes wrote: >> I guess we would need one key for you and one for Jose (we cannot share >> a LyX key). > > I have a key. But I guess it is not very authorative (due to missing counter- > signs). Well, even if your keys are not signed by anyone, it s