kernel.org no longer centrally signs submissions
kernel.org no longer centrally signs submissions
Posted Nov 9, 2011 3:11 UTC (Wed) by raven667 (subscriber, #5198)In reply to: kernel.org no longer centrally signs submissions by jimparis
Parent article: KS2011: Kernel.org report
Auto signing doesn't provide any more verification than an md5sum file which would probably be a better choice. When signatures are used people often assume a higher level of verification than really exists. Usually when releases are signed the private key is not publicly accessible and is on a separate device that only release approvers have access to, an offline workstation or smart card for example. That procedure can be a higher level of assurance that the bits you have are the right ones
