Re: [gobolinux-devel] Re: Signature of binary packages

2006-07-01 Thread Carlo Calica
On 6/28/06, Hisham Muhammad <[EMAIL PROTECTED]> wrote: On 6/28/06, MJ Ray <[EMAIL PROTECTED]> wrote: > MLA-Gobo <[EMAIL PROTECTED]> wrote: > > Ah--I think I see. So by "main keyserver network," you mean something > > like > > pgp.mit.edu or keyserver.veridis.com, right? Ok, that makes sense.

Re: [gobolinux-devel] Re: Signature of binary packages

2006-07-01 Thread Andy Feldman
On 7/1/06, Carlo Calica <[EMAIL PROTECTED]> wrote: WRT keyservers, what's preventing someone from uploading a key with an assumed name/email? Basically, how can we trust the key. Yeah I know about key signing and web of trust but making contributors go to key signing parties is a bit much. Yo

[gobolinux-devel] InstallPackage's Verify_Superuser

2006-07-01 Thread Andy Feldman
I had the idea to put off Verify_Superuser to later in the InstallPackage process, so you could check for and download packages before needing to escalate privileges. It struck me as silly that I would have to type my root password to be informed "There is no package for that program," or that the