[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: dinstall and PGP



Hi,
>>"Marco" == Marco d'Itri <md@linux.it> writes:

Marco> On Apr 08, Vincent Renardias <vincent@waw.com> wrote:

>> Anyway, I fail to see WHY we should allow non PGP signed packages.
Marco> Because it's not easy to sign .dsc and .changes files via a ssh
Marco> pipe when compiling packages on va. This is impossible when my
Marco> workstation is behind a firewall and I can't open ssh
Marco> connections to it.

	Those files are small. One can copy them back easily (using
 ftp, even), sign them locally, and upload two tiny files.

	Not enough to justify allowing non-pgp signed stuff. Am I
 missing something? 

	manoj
-- 
 "Why do men go to war?  Because women are watching." Eliot
Manoj Srivastava  <srivasta@acm.org> <http://www.datasync.com/%7Esrivasta/>
Key C7261095 fingerprint = CB D9 F4 12 68 07 E4 05  CC 2D 27 12 1D F5 E8 6E


--
To UNSUBSCRIBE, email to debian-devel-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


Reply to: