monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Re: Re: Re: How will policy branches work?


From: Jack Lloyd
Subject: Re: [Monotone-devel] Re: Re: Re: How will policy branches work?
Date: Wed, 6 Feb 2008 10:50:43 -0500
User-agent: Mutt/1.5.11

On Wed, Feb 06, 2008 at 10:43:37AM -0500, Zack Weinberg wrote:

> We think that it'll be both friendlier and more secure if we allow
> people to do whatever they want locally, but not force changes in
> violation of policy on anyone else.  It ends up working almost like
> what you describe in practice.  There is a set of permission settings
> signed (not encrypted) with the administrator's private key.  One of
> those settings is the administrator's public key.  Anyone can, in
> their own database, substitute a permission set signed with their own
> private key which lists their own public key as having administrative
> rights.  But everyone else's database ignores that change because they
> only trust the original administrator, not the usurper.

Would this also be the path for dealing with a
our-project-leader-went-evil-on-us type of situation? Everyone (who
wants to trust some other admin instead) can import a packet with the
new admin key+signature blob in it, something along those lines?

-Jack




reply via email to

[Prev in Thread] Current Thread [Next in Thread]