Ron Aaron wrote:
> On Tuesday 23 February 2010 18:16:59 D. Richard Hipp wrote:
> 
>> I get the impression that I am perhaps the only person in the world  
>> who cares about PGP signing their check-ins.  So rather than burden  
>> all other users with having to figure out PGP/GPG, what it is, how it  
>> works, and why Fossil cares about it, I think it is better to simply  
>> Fossil for the common user and leave PGP signing off by default.  This  
>> helps to make Fossil more accessible to newbies.
> 
> I would be more interested if it were possible to require the checkin be 
> signed, and perhaps if there were a way to only accept signatures from a 
> whitelist of keys.  As it is currently, though I am  a real fan of GPG I 
> don't see much utility in the way it is currently used in Fossil.

+1 for being able to require checkins be signed. Otherwise it's really
easy to get a mix of unsigned and signed checkins (if for no other
reason than one's own machine / environment is temporarily
misconfigured) that is of dubious value.

-- 
Daniel JB Clark | http://pobox.com/~dclark

_______________________________________________
fossil-users mailing list
[email protected]
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to