Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #54972
| From | Yves-Alexis Perez <corsac@debian.org> |
|---|---|
| Newsgroups | linux.debian.kernel |
| Subject | [RFC] Verify tag with gpg before extracting orig tarball |
| Date | 2016-08-30 22:20 +0200 |
| Message-ID | <sbXFM-1b9-17@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Hi there, as discussed this afternoon on IRC with Ben, I'd took a look at PGP-checking the tags when using genorig.py for extracing the kernel sources. I'm unsure how people (and especially Ben) do it nowadays, but for linux-grsec I mostly use genorig.py with git, and usually checks the tag signature before running genorig. I thought it might be a good idea to enforce this verification as part of the script, and fail if the signature fails. I've setup a branch in my own repository [1] if someone wants to take a look (I guess I can also resend with git send-email or something). [1] https://anonscm.debian.org/cgit/collab-maint/linux-grsec.git/log/?h=gpg-ta g-check Regards, -- Yves-Alexis
Back to linux.debian.kernel | Previous | Next | Find similar | Unroll thread
[RFC] Verify tag with gpg before extracting orig tarball Yves-Alexis Perez <corsac@debian.org> - 2016-08-30 22:20 +0200
csiph-web