[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: fakeroot a solution for multi-architecture building?



On Mon, 29 Sep 1997, Dale Scheetz wrote:

>I agree that the machine should be given a pgp key, but an individual
>should be the party responsible for its invocation. A vulnerable machine
>with its activities determined by a set of cron jobs is not something we
>should "identify" as a "developer".

The machine will not have a pgp key. The special packaging account will
have one. Packages will be build under one special user account which can
be protected with a directory mode 700 on top so that no one can spy into
things.

I do not think that these partition mounting things etc are necessary.
Lets get it to work first and then see what additional measures re
security might be necessary.

I'd rather see us implementing the multi-arch automated builders than
talking them to death.

 --- +++ --- +++ --- +++ --- +++ --- +++ --- +++ --- +++ ---


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-devel-request@lists.debian.org . 
Trouble?  e-mail to templin@bucknell.edu .


Reply to: