Re: [Rpm-maint] [rpm-software-management/rpm] Phasing out obsolete crypto in rpm (#1292)

2020-12-25 Thread Demi Marie Obenour
> > > Besides the currently obsolete things, new things need to be built with > > > the mindset that all crypto _will_ become obsolete over time, and avoid > > > putting it into new places where it only gets in our way eventually. > > > > > > I suggest avoiding algorithm agility as much as

Re: [Rpm-maint] [rpm-software-management/rpm] Phasing out obsolete crypto in rpm (#1292)

2020-12-25 Thread ニール・ゴンパ
> > Besides the currently obsolete things, new things need to be built with the > > mindset that all crypto _will_ become obsolete over time, and avoid putting > > it into new places where it only gets in our way eventually. > > I suggest avoiding algorithm agility as much as possible. It is

Re: [Rpm-maint] [rpm-software-management/rpm] Cannot import a GPG key with signatures (#1306)

2020-12-25 Thread ニール・ゴンパ
> > Yes, this is a known - or not so well known - limitation. As the signature > > check is basically done by hand it lack a lot of feature one would expect > > of GPG proper. > > Can we (as an option) use a third-party library, such as [rpgp](/rpgp/rpgp)? Rust is not acceptable due to its

Re: [Rpm-maint] [rpm-software-management/rpm] RFE: Signing packages with signify (#1193)

2020-12-25 Thread Demi Marie Obenour
Much of the complexity in PKCS#7, PKCS#12, and OpenPGP comes from being too flexible. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: