On Fri, Jan 17, 2014 at 09:59:03AM +0100, Sébastien Marie wrote: > On Thu, Jan 16, 2014 at 10:02:22AM +0000, Stuart Henderson wrote: > > On 2014/01/16 08:53, Sébastien Marie wrote: > > > Hi, > > > > > > Does it make sens to have an option to require package to be signed ? > > > > It makes more sense to just enable that by default, when we are happy > > with the infrastructure and usage. > > > > I saw "enable by default" more as long term purpose. The patch would > permit to easily test it...
Enable by default is trivial to do. Look around the code that says "check_signature" in OpenBSD/PkgAdd.pm, I'm sure you can figure out the change.