On 04/ 1/10 03:52 AM, Rainer Orth wrote:
Shawn,

There are several things I'd like to point out:

   * The application/pkg/server service is disabled by default, an
     administrator has to enable it explicitly; that suggests that
     they've read the documentation and are aware and intend that
     publication access is enabled.  Changing the default for readonly
     is fine, although again, this doesn't resolve the administrator
     of their responsibilities.

indeed, but this can only happen if they are fully aware of the
consequences.  I still claim that documentation for this is lacking,
especially since the problem has been known from the start.

Part of the problem with a rapidly evolving project is that the documentation becomes very stale, very quickly. It's difficult to provide suggestions or recommendations to users when what the suggested method is continually evolves.

Recommended solutions also take time to test, document, and provide, and once provided have to become supported. At this stage in the project, enough functionality is not yet implemented that providing any significant material in this area would not be beneficial.

This is why generally, this sort of information has been provided as it has been requested, as opposed to officially documenting/supporting it.

...
   * When package signing is implemented, even if you could somehow
     publish a new package to a repository, clients would reject it
     since it wasn't properly signed.

I've been hoping for this for a long time: SVr4 packaging gained this
ability quite some time ago, so IPS is regressing in this crucial
regard.

Again, in-devlopment project, not yet feature complete. The in-development status is documented in the man page(s).

Some functionality can not yet be implemented since some parts of the system it would need to account for are also not yet implemented. In addition, as you might imagine, cryptographic work tends to have non-technical components that have to be addressed.

-Shawn
_______________________________________________
caiman-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/caiman-discuss

Reply via email to