Re: Contributed packages and trust problem ? - Mailing list pgadmin-hackers

From Raphaël Enrici
Subject Re: Contributed packages and trust problem ?
Date
Msg-id 3F356A49.7040909@club-internet.fr
Whole thread Raw
In response to Re: Contributed packages and trust problem ?  ("Dave Page" <dpage@vale-housing.co.uk>)
Responses Re: Contributed packages and trust problem ?  ("Dave Page" <dpage@vale-housing.co.uk>)
List pgadmin-hackers
Dave Page wrote:

>>-----Original Message-----
>>From: Raphaël Enrici [mailto:blacknoz@club-internet.fr]
>>Sent: 09 August 2003 19:14
>>To: pgadmin-hackers@postgresql.org
>>Subject: [pgadmin-hackers] Contributed packages and trust problem ?
>>
>>
>>Giuseppe Sacco
>>contributed today a build of the debian packages for PowerPC
>>architecture based on our Debian Source packages. As he is a
>>member of
>>the debian project, I think we can consider him as a trusty
>>person. But
>>what about other persons that may contribute builds for other
>>architectures ? Did you faced this "problem" in the past ?
>>
>>
>Never considered it in the past as I always did the builds. I think it is a valid problem though. Is there any way we
cansign the source code such that when it's compiled we can verify that it was unmodified source? 
>
Never heard about something like this....


>>Is there something done for the moment ? Shall someone sign
>>the files ? Shall every packager sign its own package ? I'm currently
>>looking to what's done in Debian and will give you some
>>feedback on it.
>>
>>
>What did you have in mind, a pgp sig for each file? I don't see that as a problem for each packager to create.
>
>
As RPM and DEB packages integrates gpg signatures, I just wanted to know
if their were a pgp/gpg key global to the pgAdmin team, something that
was used to sign the files of the project like binaries, sources, etc.
I'm ok to sign deb package by myself.
And wanted to know if you used by the past to sign the files ? For
example the source tarball and win32 packages.

Regards,

Raphaël



pgadmin-hackers by date:

Previous
From: Raphaël Enrici
Date:
Subject: Re: Package naming conventions
Next
From: Andreas Pflug
Date:
Subject: Re: Package naming conventions