>sorry for my ignorance, but aren't PGP signatures included in every RPM ?
>I think when you are installing the rpm the rpm verifies the signature.

every RPM *can* be PGP signed... not all are.
rpm *can* verify the signature of a signed RPM, *IFF* you have pgp installed,
and ask it to do so. Redhat does not ship PGP; that's what hpa meant by having
to download it yourself.

>I am missing something ?
>
>Is GnuPG the solution of the US export-control problems ?

You mean GnuPGP? if it can be obtained outside the US, and it can perform
the same level of verification as pgp can inside the US, then yeah I don't
see why not.

  cabbey at home dot net <*> http://members.home.net/cabbey
           I want a binary interface to the brain!
Today's opto-mechanical digital interfaces are just too slow!

-- 
To unsubscribe:
mail -s unsubscribe [EMAIL PROTECTED] < /dev/null

Reply via email to