Re: [Gnu-arch-users] Re: signatures and checking

From: Tom Lord
Subject: Re: [Gnu-arch-users] Re: signatures and checking
Date: Mon, 26 Jan 2004 17:45:47 -0800 (PST)

    > From: Samuel Tardieu <address@hidden>

    > >>>>> "Tom" == Tom Lord <address@hidden> writes:

    > > 1. Checksum data can be reliably extracted from them by tla
    > > _even_if_ the user has no ~/.arch-params/.../*.check file for the
    > > relevent archive.

    > > 2. They are "all in one" -- tla can read them, along with the
    > > signature, in a single file-fetch from the archive.  In other words,
    > > detached signatures are not an option.

    > Wouldn't a tar file with checksums + detached signatures achieve what
    > you want? It does 1, it does 2, and it fixes the flaws that were
    > identified.

You're correct that that satisfies the requirements.   On the other
hand, it seems rather heavyweight and it would require using the
filesystem to invoke .check and signing scripts.


