Re: PGP signing releases

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: PGP signing releases
Дата
Msg-id Pine.LNX.4.44.0302101523510.6138-100000@peter.localdomain
обсуждение исходный текст
Ответ на Re: PGP signing releases  (Curt Sampson <cjs@cynic.net>)
Ответы Re: PGP signing releases
Список pgsql-hackers
Curt Sampson writes:

> MD5, or any other unsigned check, makes sense from a security point of
> view only if it is stored independently from the thing you are checking.

So you put the MD5 sum into the release announcement email.  That is
downloaded by many people and also archived in many distributed places
that we don't control, so it would be very hard to tamper with.  ISTM that
this gives you the same result as a PGP signature but with much less
administrative overhead.

-- 
Peter Eisentraut   peter_e@gmx.net



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: pg_dump is broken by recent privileges changes
Следующее
От: Peter Eisentraut
Дата:
Сообщение: Re: 7.2 -> 7.3 incompatibility