git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Lack of detached signatures

From
JPJoseph Parmelee <jparmele@wildbear.com>
Date
Sep 29, 2011, 01:29 UTC
Message-ID
<alpine.LNX.2.00.1109281914510.29373@bruno>
In-Reply-To
<20110928230958.GJ19250@thunk.org>
On Wed, 28 Sep 2011, Ted Ts'o wrote:
Show 18 quoted lines
> On Wed, Sep 28, 2011 at 06:25:43PM -0400, Jeff King wrote:
>> [1] This is a minor nit, and probably not worth breaking away from the
>> way the rest of the world does it, but it is somewhat silly to sign the
>> compressed data. I couldn't care less about the exact bytes in the
>> compressed version; what I care about is the actual tar file. The
>> compression is just a transport.
>
> The worry I have is that many users don't check the GPG checksum files
> as it is.  If they have to decompress the file, and then run gpg to
> check the checksum, they might never get around to doing it.
>
> That being said, I'm not sure I have a good solution.  One is to ship
> the file without using detached signatures, and ship a foo.tar.gz.gpg
> file, and force them to use GPG to unwrap the file before it can be
> unpacked.  But users would yell and scream if we did that...
>
> 	       	     	   	    	   - Ted
>

Or you could just provide detached signatures for the compressed tarballs like they have been doing for years at kernel.org (and many other sites). If tarball.tar.bz2 has a detached signature tarball.tar.bz2.sig, just download them both and:

   gpg --verify tarball.tar.gz.sig

To argue that some people don't avail themselves of this feature is no excuse for not providing it for those of us who consider it vital. The break in at k.o is no excuse for dropping this very sensible policy which has protected us for years. Just change the signing key and continue as before.

Previous: Joseph ParmeleeNext: Jeff King
Message 20 of 24 in “Lack of detached signatures”
  1. Joseph ParmeleeSep 27, 2011
  2. Junio C HamanoSep 28, 2011
  3. Michael WittenSep 28, 2011
  4. Olsen, Alan RSep 28, 2011
  5. Carlos Martín NietoSep 28, 2011
  6. Joseph ParmeleeSep 28, 2011
  7. Junio C HamanoSep 28, 2011
  8. Michael WittenSep 28, 2011
  9. Matthieu MoySep 28, 2011
  10. Jeff KingSep 28, 2011
  11. Ted Ts'oSep 28, 2011
  12. Junio C HamanoSep 29, 2011
  13. Ted Ts'oSep 29, 2011
  14. Junio C HamanoSep 29, 2011
  15. Ted Ts'oSep 29, 2011
  16. Sverre RabbelierSep 29, 2011
  17. Ted Ts'oSep 29, 2011
  18. Sverre RabbelierSep 29, 2011
  19. Joseph ParmeleeSep 29, 2011
  20. Joseph ParmeleeSep 29, 2011
  21. Jeff KingSep 29, 2011
  22. Olsen, Alan RSep 29, 2011
  23. Joseph ParmeleeSep 28, 2011
  24. Ben WaltonSep 28, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.