>>>>> "RHJ" == Robin H Johnson <[email protected]> writes:

>> Include the signing keyid in the filename to support both allowing
>> multiple devs to sign a file and an easy indication of who signed it.

RHJ> You can extract keyid from any signature trivially.

But if it is not in the filename you cannot have multiple sig files.

>> Don't stop everything just because /one/ package has a problem.

RHJ> This is already controllable.

If you mean --keep-going, that may work sometimes, but never did when I
really needed it.

>> And think about a way to sign Changelog entries.

RHJ> We wanted commit-signing with the git migration...

Good choice.

-JimC
-- 
James Cloos <[email protected]>         OpenPGP: 1024D/ED7DAEA6

Reply via email to