LWN.net Logo

Signed packages alone is not sufficient to protect the system from malicious software...

Signed packages alone is not sufficient to protect the system from malicious software...

Posted Nov 20, 2009 14:55 UTC (Fri) by skvidal (subscriber, #3094)
In reply to: Signed packages alone is not sufficient to protect the system from malicious software... by drag
Parent article: Fedora 12 lets unprivileged users install packages

metalinks are the default mechanism for getting the mirrorlist from fedora. They are accessed over https and urlgrabber in f12 checks certificates properly.
So, yes, that's done.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds