savannah-hackers
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Savannah-hackers] Detached signatures for source files


From: Elfyn McBratney
Subject: Re: [Savannah-hackers] Detached signatures for source files
Date: Sun, 26 Sep 2004 12:13:43 +0100
User-agent: KMail/1.6.2

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

Apologies for lumping the replies together, it's easier for me to keep track 
of them this way ;-)

On Saturday 25 Sep 2004 13:49, Brian Gough wrote:
> "Laurence Finston" <address@hidden> writes:
> > I'd like put a subdirectory in each subdirectory in my repository
> > with a detached GPG signature for each source file.  Each signature
> > file should have the same revision number as the corresponding
> > source file.

This is possible.  We have a system where you can use triplicate directive 
files that can specify a destination directory, the signed file and it's 
signature.  It's not totally tested, but I guess you could test it out for 
your project. :-)

> Laurence, is this for a special application or are you trying to
> implement a form of GPG commit signing?
>
> For signing multiple files there is a gpg-agent in the development
> version of GPG, but there may be better ways since signing the
> contents of the files does not protect against metadata attacks.

Yeah, there's also a gpg-agent howto in the FAQ at Savannah, in case it helps 
for this sorta' stuff. :-)

Best,
Elfyn

- -- 
Elfyn McBratney
beu on irc.freenode.net/savannah.[non]gnu.org

PGP Key ID: 0x456548B4
PGP Key Fingerprint:
  29D5 91BB 8748 7CC9 650F 31FE 6888 0C2A 4565 48B4
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBVqRnaIgMKkVlSLQRAjRKAJ0S+ggfu4zxMIvzhKvCUU4fNgzxWwCfUmP1
lGZCEn7vDMZQYFHsHK3n/t8=
=hoL1
-----END PGP SIGNATURE-----




reply via email to

[Prev in Thread] Current Thread [Next in Thread]