|
|
Subscribe / Log in / New account

kernel.org no longer centrally signs submissions

kernel.org no longer centrally signs submissions

Posted Nov 9, 2011 3:11 UTC (Wed) by raven667 (subscriber, #5198)
In reply to: kernel.org no longer centrally signs submissions by jimparis
Parent article: KS2011: Kernel.org report

Just to be clear, an automatic signature _only_ tells you that the bits passed through kernel.org. If you download from kernel.org then it tells you exactly nothing. I'm not sure why you mention ssl, it seems that ssl provides a higher level of assurance and what ssl provides is pretty lame.

Auto signing doesn't provide any more verification than an md5sum file which would probably be a better choice. When signatures are used people often assume a higher level of verification than really exists. Usually when releases are signed the private key is not publicly accessible and is on a separate device that only release approvers have access to, an offline workstation or smart card for example. That procedure can be a higher level of assurance that the bits you have are the right ones


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds