Reflections on Trusting Trust

Kris Kennaway kris at obsecurity.org
Wed Nov 30 00:04:10 GMT 2005


On Tue, Nov 29, 2005 at 03:44:46PM -0800, Colin Percival wrote:
> Kris Kennaway wrote:
> > Also, pkg_sign(1) has existed for a long time, but needs the support
> > infrastructure to make it usable.
> 
> Last I heard, pkg_sign(1) became non-functional when we changed from
> gzipped tarballs to bzip2ed tarballs for packages.

Yeah, that could well be true.

Kris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20051129/c008909f/attachment.bin


More information about the freebsd-security mailing list