public inbox for gcc@gcc.gnu.org
 help / color / mirror / Atom feed
* gcc dependency on unsigned mpc releases
@ 2010-04-28 16:56 Brian Gough
  2010-04-30 14:25 ` [Mpc-discuss] " Andreas Enge
  0 siblings, 1 reply; 2+ messages in thread
From: Brian Gough @ 2010-04-28 16:56 UTC (permalink / raw)
  To: mpc-discuss; +Cc: gcc

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

I am just following up on my earlier email to mpc-discuss to check if
some signatures can be made available for the mpc tarballs.  Currently
it's not possible to install the latest gcc without the risk of using
unsigned code.  Thanks.

- --
Brian Gough

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.15 (GNU/Linux)

iJwEAQECAAYFAkvYWhsACgkQ9U2K2oCCH+r+7AP/b/KnQGMhIgusSe9l8wZQ9cP1
HgeG0s1cDrjqi3jrDtNy8OlvVMaeqYbByWu/sLKwfCCkB+db2KD10MQSBhfzMKV7
ER9IQXpQPu24NxiPvWhP/wSJJd7/WqvlNqwxpcvXG30iiw0kQT5wmt28if7n8ojc
YIDH7wJYNZcKonD5P/U=
=eON1
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [Mpc-discuss] gcc dependency on unsigned mpc releases
  2010-04-28 16:56 gcc dependency on unsigned mpc releases Brian Gough
@ 2010-04-30 14:25 ` Andreas Enge
  0 siblings, 0 replies; 2+ messages in thread
From: Andreas Enge @ 2010-04-30 14:25 UTC (permalink / raw)
  To: Discussions around mpc; +Cc: gcc

Hi,

On Wed, Apr 28, 2010 at 11:54:45AM -0400, Brian Gough wrote:
> I am just following up on my earlier email to mpc-discuss to check if
> some signatures can be made available for the mpc tarballs.  Currently
> it's not possible to install the latest gcc without the risk of using
> unsigned code.  Thanks.

why not. Is there any gnu policy on how these signatures need to be
created? Can I sign with any gpg key, or does it have to be related
to the domain on which mpc is hosted?

My main practical concern is how to establish a trust path; as long as
there are no signatures on my key, signing hardly increases security
compared to a static hash sum (which I just published on the mpc page).

Andreas

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2010-04-30 14:19 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-04-28 16:56 gcc dependency on unsigned mpc releases Brian Gough
2010-04-30 14:25 ` [Mpc-discuss] " Andreas Enge

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).