Elaine -HFB- Ashton wrote: > Jeremy Wadsack [[EMAIL PROTECTED]] quoth: > *> > *>> A signature by PAUSE is an interesting idea. But it would tell the > *>> user something different than a signature by a person. While I imagine > *>> that a sig by GBARR would mean something like: "I have written or at > *>> least doublechecked the code in this package to be free from malicious > *>> intent. This is not a warranty." (careful considerations about wording > *>> pending). A signature of the PAUSE could only mean "These checksums > *>> were valid at the time of the upload." > *> > *>Again, my problem with requiring user signatures is that it complicates > *>the module distribution process. Unless there's a really EASY way for > *>people to acquire a signature and apply it to their modules, you're going > *>to just increase the attrition in Perl developers. > > Hang on, don't get too excited just yet as these are just ideas being > tossed around. ... I need more coffee, but these are simply ideas at this > point, no need to get your panties in a bunch over letting your imagination > go in the attempt to find something that really make CPAN a really useable > space. Uh.. I didn't mean for that to appear a flame. Perhaps I'm not into the whole brainstorming idea, but I wanted to bring into light what I considered a potentially likely response to digital signatures. Perhaps, I should have been more politic and (more explicitely) suggested a solution along with my concerns. Specifically, I was thinking: > We could build some sort of PKI with minimal resources. And some sort of tie-in to MakeMaker that automatically retrieves the signature or assignes one if none is already registered. In other-words, making the signing process vitually transparent to the developer. This would be cool and allow securing code. Jeremy Wadsack Wadsack-Allen Digital Group

