[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-release-team
Subject:    Re: Proposal: Implementing signing process for official tarballs (try
From:       Tom Albers <toma () kde ! org>
Date:       2010-05-30 10:04:23
Message-ID: 4e7c115c18276a35f6acdf811b94d6f4 () imap ! kovoks ! nl
[Download RAW message or body]


On Fri, 28 May 2010 23:32:58 +0200, Dirk Mueller <mueller@kde.org> wrote:
> I'm fine with providing a signature again, but fact is that nobody
> requested 
> them again so far. Just providing the md5sums on the website was enough
so
> far 
> - people are mostly concerned about incomplete/wrong downloads rather
than 
> malicious attacks. 

I'ld be in favor to reintroduce it again. Although I'm happy with a simple
setup. Signing with your personal key would be ok for me, provided we
mention that on the info page, which resides in svn.

Best,
-- 
Tom Albers
KDE Developer
_______________________________________________
release-team mailing list
release-team@kde.org
https://mail.kde.org/mailman/listinfo/release-team
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic