Package signing: database signatures?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



Hello everybody,

afaik, database files in official repositories are not signed yet. Are they?

This forces one to set SigLevel to 'Optional' instead of 'Required'. Now if
anybody wants to provide an infected package he/she only needs to provide no
signature at all and the package is happily accepted, no?

So when will database files from official packages be signed?

And even more interesting: Does it make sense to add a new option
'PkgRequired'? This could force valid signatures for packages and make it
optional for database files.
-- 
Best regards,
Chris
                         O< ascii ribbon campaign
                   stop html mail - www.asciiribbon.org


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux