On Tue, Apr 4, 2017 at 12:03 PM, Andreas K. Huettel <[email protected]> wrote: >> while we're discussing super-strength hash algos, it would be cool to know >> what's still missing for >> * rsync-side manifest signing in whatever way >> * verification of such signatures in portage / emerge >> > > (and just to put it in a reference frame, I'm these days reading mailing list > discussions how cryptographic signing of our rsync tree is urgently needed... > ... in the council agenda threads > ... of the very first council > ... i.e., 2005 > ... i.e., roughly 12 years ago.)
Was thinking exactly the same thing yesterday. How do we make it happen? Do we have any ideas on feasible paths forward? Cheers, Dirkjan
