Time to resurrect multi-key signatures in RPM?

Joshua C. joshuacov at googlemail.com
Wed Aug 27 23:31:49 UTC 2008


This is an interesting idea. Cross checking on multiple build mashines
with private signed email (containg the checksums of source and
binary, stripped away from machine specific data) send to the
signatories - this all makes it alot difficult for someone to crack.




More information about the fedora-devel-list mailing list