home  bbs  files  messages ]

      ZZLI4428             linux.debian.maint.dpkg             86 messages      

[ previous | next | reply ]

[ list messages | list forums ]

  Msg # 26 of 86 on ZZLI4428, Wednesday 9-02-25, 1:18  
  From: SIMON JOSEFSSON  
  To: GUILLEM JOVER  
  Subj: Re: RFC: Consequences of redesign of .de  
 XPost: linux.debian.devel 
 From: simon@josefsson.org 
  
 Guillem Jover  writes: 
  
 >  * Make the format extensible to other signature formats or workflows 
 >    (such as x509, secure-boot, IMA, etc., even if there's currently no 
 >    intention to add support for any of this). 
  
 I think this is a useful goal to make sure there is no PGP specific 
 assumption lurking.  The SSH signature format is low complexity, stable 
 and widely implemented, so maybe supporting this would be possible?  If 
 there is a framework to plug things into I may put some cycles into 
 implementing SSHSIG support.  I think supporting Sigstore and Sigsum 
 verification would be useful too, since I think in the coming years 
 we'll look at non-transparency-signed software releases in a similar way 
 that we look at non-signed software releases today. 
  
 /Simon 
  
 -----BEGIN PGP SIGNATURE----- 
  
 iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmi1hoMUHHNpbW9uQGpv 
 c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f 
 V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z 
 ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh 
 BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA 
 /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx 
 +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx 
 I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 
 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R 
 cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 
 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J 
 ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 
 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB 
 BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA 
 JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF 
 PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh 
 is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFoseFAQDmDdlAEazE 
 WrAZFqXbdAbkmSOJQ0S2mG7FZ6PQwmt//QD/e4x6JLcx7NheqvqvKpLQvi9gMfGt 
 FGX6pN5FT32TsAM= 
 =uKYa 
 -----END PGP SIGNATURE----- 
  
 --- SoupGate-Win32 v1.05 
  * Origin: you cannot sedate... all the things you hate (1:229/2) 

[ list messages | list forums | previous | next | reply ]

search for:

328,091 visits
(c) 1994,  bbs@darkrealms.ca