LWN.net Logo

Closing the window of attack

Closing the window of attack

Posted Aug 30, 2008 0:02 UTC (Sat) by bojan (subscriber, #14302)
In reply to: Closing the window of attack by Sutoka
Parent article: The proposed Fedora key-migration plan

> In the future, Fedora might wanna have multiple keys.

If Fedora packages were signed by multiple independent signatories, yum could be designed to accept (for instance) only packages signed like this:

- Fedora key
- at least 2 other keys from independent signatories

or

- 5 keys from independent signatories

In that case, a compromise of a single key would be easily avoided, as long as you had enough signatories in the pool to make up the numbers (and with vast number of people involved in Fedora, this is definitely possible).


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds