On Sat, 2004-10-30 at 01:11 +0200, Matias F�ciano wrote: > Since rawhide have some unsigned packages I like to know which package > is not signed and I sign them with my key (so yum always have > "gpgcheck=1") : > I mirror rawhide in the i386 directory with rsync, and then I sign > package that miss gpg. > Note, I don't sign (that is, change) any package in i386 directory > (rsync does not like this). When somebody organizes a man-in-the-middle attack between you and whichever site you rsync rawhide from , you sign the packages anyway. Can you see how this is a big problem? -- Peter