Good evening folks,

in the past I witnessed bits and pieces of attempts to increase the
infrastructure userside, but, unless I'm mistaken, there's still room
for improvement.

Since a couple of years we have the webrsync-gpg FEATURE, which enables
automatic verification of the portage tree, when updated via webrsync.

We also have mandatory signing via gpg of packages, news items and (I
strongly suspect) GLSAs for maintainers. Yet, there's not checking
mechanism whatsoever in portage.

Now my question: are there plans existing on how to improve this
situation? Any project that might be involved with such plans?
In particular, my question is with respect to
- automatic verififcation of the gpg-signatures provided when syncing
via git
- development of a verification scheme that works just as well with rsync
- on the threat-assessment side: are there dangers involved, apart from
a mitm-attack between the (rsyncing) end-user and a mirror or a mirror
and the main servers?

Thank you for your time.

With kind regards,
tomboy64

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to