[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#93612: Support for new archive structure



On Thu, 12 Apr 2001, J.A. Bezemer wrote:

**** 

> So I think we should continue to generate _correct_ Packages files for
> each CD, and solve the "signing issue" using some other method. 

I repeat my earlier suggestion. Sign md5sums.gz, this is supposed to be
the accuracy and security file.  A script could be provided for the
paranoid to check the CD, mirror or whatever.  Then Packages can be built
to reflect the needs of CDs, partial mirrors, local file systems and the
rest.  Packages are primarly created to aid installations and were not
intended to be a security tool.  As far as I can see, the md5sums in
Packages are there because they are in the control files.

Phil.

-
  Philip Charles; 39a Paterson St., Dunedin, New Zealand; +64 3 4882818
Mobile 025 267 9420.  I sell GNU/Linux CDs.   See http://www.copyleft.co.nz
     philipc@copyleft.co.nz - preferred.           philipc@debian.org



Reply to: