Re: PGP signing releases

Поиск
Список
Период
Сортировка
От Neil Conway
Тема Re: PGP signing releases
Дата
Msg-id 1044291075.25210.933.camel@tokyo
обсуждение исходный текст
Ответ на Re: PGP signing releases  ("Marc G. Fournier" <scrappy@hub.org>)
Ответы Re: PGP signing releases  (Rod Taylor <rbt@rbt.ca>)
Список pgsql-hackers
On Sun, 2003-02-02 at 21:23, Marc G. Fournier wrote:
> well, if you want to tell me the steps, I'll consider it ...

I certainly wouldn't consider myself to be an expert in PGP, but my
understanding of the basic steps is:

(1) Generate a public/private key pair for the PGDG team. This should be
used to sign all "official" packages.

(2) Have this PK signed by various people who can actually verify that
Marc Fournier == 'that PGP key' == 'PGDG member'.

(2) Upload the public key to PGP keyservers, like keyserver.net,
www.pgp.net, etc. as well as provide a copy of the public key on
www.postgresql.org and ftp.postgresql.org

(3) Sign official releases using the PGDG private key, and provide the
signatures on www.postgresql.org along with the packages themselves.

If someone more experienced in the use of PGP would like to comment,
please go ahead.

Cheers,

Neil
-- 
Neil Conway <neilc@samurai.com> || PGP Key ID: DB3C29FC





В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Dave Page"
Дата:
Сообщение: Win32 Powerfail testing - results
Следующее
От: Rod Taylor
Дата:
Сообщение: Re: PGP signing releases