Yes, that's what I gathered was meant. Going into PKI and code signing,
however, I assumed he meant signing and verifying the underlying source
code, and navigating the trees, I haven't noticed that.Evidently he meant signing binary packages. In that case, I can kind of
understand the requirement - particularly for business - but whether it's
worth it is up to the OpenBSD team, not me. :) I'm having trouble seeing how
somebody could easily manage to get a compromised binary onto OpenBSD
servers. Seems more trouble to implement then it's worth.On Dec 5, 2007 7:13 PM, Dave Ewart wrote:
> On Wednesday, 05.12.2007 at 17:59 +0000, Kevin Stam wrote:
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Andrew Morton | Re: -mm merge plans for 2.6.23 -- sys_fallocate |
| Greg KH | Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching |
git: | |
| Gerrit Renker | [PATCH 03/37] dccp: List management for new feature negotiation |
| Arjan van de Ven | Re: [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Jarek Poplawski | Re: [BUG] New Kernel Bugs |
