Henning Schmiedehausen wrote: > So you assume that that www.apache.org can not be hacked? What if a > signing key *IS* in KEYS but not signed by anyone (because the developer > has never attended an Apache key signing event)?
No, I answered your question. W.r.t. www.apache.org/dist/{tlp}/KEYS, we have a serious issue to address, because it's not https: accessible so cannot be trusted. Yes, it's quite possible to fetch https://svn.apache.org/repos/asf/{tlp}/{code}/trunk/KEYS but that's not what we suggest, and suboptimal to boot. The bigger problem is that you appear to be arguing against solving the problem rather than offering solutions, and I recall some have suggested that this thread should die already. Maybe time to take this to maven where it belongs? --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]