[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Suggest another way of importing GNU Guix GPG key

From: Giovanni Biscuolo
Subject: Re: Suggest another way of importing GNU Guix GPG key
Date: Sun, 30 Jun 2019 11:44:04 +0200

Hello Guix!

Alex Vong <address@hidden> writes:

> One solution would be to download the keyring from
> <> and verify the signature in
> the following way:
>   $ gpg --keyring ./gnu-keyring.gpg --verify guix-1.0.1.tar.gz.sig 
> guix-1.0.1.tar.gz

Correct, the quick and "dirty" workaround is **to stop using the SKS
network** and warn Guix users to **manually download** certificates

This means we should quckly patch Guix manual: I've no time to propose a
patch today, I'll work on this tomorrow

We also nees to address this for **all** guix contributors: we require a
GPG signed commit, so each and every contributor/developer should
understand the risks of using SKS network and apply current proposed
workarounds: can we state this in maintenance.git/HACKING?

We sould act qulckly, IMHO

Thanks! Gio'


Giovanni Biscuolo

Xelera IT Infrastructures

Attachment: signature.asc
Description: PGP signature

reply via email to

[Prev in Thread] Current Thread [Next in Thread]