Shawn Walker wrote:

> >>    Please note that the digest and cryptographic information is
> >>    optional since older repositories won't have the information and
> >>    some users of the depot software may choose to not provide it.
> >
> >While some users of the depot software may choose not to sign manifests
> >or catalogs, I think that digests should not be optional, except when
> >there are signatures.  Running without digests seems like pointless
> >no-pants mode.
> 
> Older depots won't provide us with the digests either, that's the other
> reason they're optional.  I could clarify this by stating that
> repositories that offer version 1 catalogs must provide the digest, but
> signatures are optional for them.  Would that be acceptable?

Yep.

Danek
_______________________________________________
pkg-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/pkg-discuss

Reply via email to