On Fri, May 06, 2016 at 01:14:22AM +0200, M.B. wrote:
> Good evening folks,
> 
> in the past I witnessed bits and pieces of attempts to increase the
> infrastructure userside, but, unless I'm mistaken, there's still room
> for improvement.
> 
> Since a couple of years we have the webrsync-gpg FEATURE, which enables
> automatic verification of the portage tree, when updated via webrsync.
> 
> We also have mandatory signing via gpg of packages, news items and (I
> strongly suspect) GLSAs for maintainers. Yet, there's not checking
> mechanism whatsoever in portage.
Portage _can_ check signed Manifests, it's just presently not doing so
as even less of the manifests are signed than they used to be with the
Git migration (read on).

> Now my question: are there plans existing on how to improve this
> situation? Any project that might be involved with such plans?
> In particular, my question is with respect to
> - automatic verififcation of the gpg-signatures provided when syncing
> via git
Use gkeys and you should have all the keys needed to verify the commits.

> - development of a verification scheme that works just as well with rsync
> - on the threat-assessment side: are there dangers involved, apart from
> a mitm-attack between the (rsyncing) end-user and a mirror or a mirror
> and the main servers?
Read the MetaManifest GLEPs, this was already planned & proposed years
ago, and hopefully at the end of this GSoC, the final implementation
pieces will be done too.

Most importantly, MetaManifest will reduce the need of signing every
single Manifest, to just signing a single top-level (meta)manifest.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Infrastructure Lead, Foundation Trustee
E-Mail     : [email protected]
GnuPG FP   : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85

Reply via email to