Re: Applying the GPG web-of-trust to Guix (was Re: Signed archives)

2014-02-21 Thread Ludovic Courtès
Mark H Weaver skribis: > Nikita Karetnikov writes: > >> 3. How does a user get Hydra’s public key? >> >> 4. Will the entire cache be signed with a single key? (Mark, would you >>like to add something?) > > FWIW, I think it's a mistake to have Hydra sign all binaries. Doing > this would mak

Applying the GPG web-of-trust to Guix (was Re: Signed archives)

2014-02-21 Thread Mark H Weaver
Nikita Karetnikov writes: > 3. How does a user get Hydra’s public key? > > 4. Will the entire cache be signed with a single key? (Mark, would you >like to add something?) FWIW, I think it's a mistake to have Hydra sign all binaries. Doing this would make Hydra a single-point of failure, an