Re: Plans to add signing ?
From: Tom Lord <lord_at_emf.net>
Date: 2003-12-11 19:29:08 CET
> From: solo turn <soloturn99@yahoo.com>
> i always assumed adding "signing" is basically a non-issue as
[...]
> if i'm not wrong this allows:
Do I understand correctly that you are suggesting just attributing
Logically, that works just fine. Pragmatically, I think it creates a
The topic has come up lately because various project hosts have been
I think that in the long run the fix people are moving towards will
a) making sure (to the limits of key mgt.) that all new
b) making sure that no old entries have been modified
with both (a) and (b) happening both on an ongoing basis in the
That's fine and signing individual files can accompilsh that in
To validate the project host after a known compromise, for example,
It doesn't work just to let clients do all the verification on
-t
---------------------------------------------------------------------
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.