Re: PGP signing releases - Mailing list pgsql-hackers

From Andrew Dunstan
Subject Re: PGP signing releases
Date
Msg-id 001f01c2ccb7$a1d50950$6401a8c0@DUNSLANE
Whole thread Raw
In response to PGP signing releases  (Neil Conway <neilc@samurai.com>)
List pgsql-hackers
----- Original Message -----
From: "Kurt Roeckx" <Q@ping.be>
>
> Should I point out that a "fingerprint" is nothing more than a
> hash?
>

If somebody shows you their passport to prove who they are and then gives
you a fingerprint of their PGP key, they have implicitly signed that
fingerprint. By contrast, a simple MD5 checksum of a binary sitting on the
same server is effectively unsigned.

You might like to do a little reading on PKI and how it works, before you
make further comment.

cheers

andrew



pgsql-hackers by date:

Previous
From: "Christopher Kings-Lynne"
Date:
Subject: Re: [GENERAL] HELP NEEDED: Recreating DROP columns
Next
From: Tatsuo Ishii
Date:
Subject: Re: POSIX regex performance bug in 7.3 Vs. 7.2