Re: Time for new release?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



> 
> However: Distributing a pacman keychain master key to more than one machine is
> rarely a sensible solution. If you actually want the very specific additional
> security checks offered by only allowing signed packages, you must ensure a
> properly secured master key with a diligently confirmed web of trust. If the
> private master key, which is being generated with --init, leaks, it is trivial
> for a hypothetical attacker to directly sign manipulated packages with this
> key, which basically invalidates the security benefit signed packages are
> supposed to offer.

Good point, I though about this one too, but what about automatic `pacman-key --init' at install time? This would solve the problem no?

[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux