WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

[Xen-devel] request to sign software

To: "xen-devel@xxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxx>
Subject: [Xen-devel] request to sign software
From: Joanna Rutkowska <joanna@xxxxxxxxxxxxxxxxxxxxxx>
Date: Sun, 28 Mar 2010 12:02:00 +0200
Delivery-date: Sun, 28 Mar 2010 03:02:08 -0700
Dkim-signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=messagingengine.com; h=message-id:date:from:mime-version:to:subject:content-type; s=smtpout; bh=/8W32ZtLUl2scOxfFyfVpwhwW1A=; b=oortZkEHPZzDtIwJOkqDVsg/KvRcnEl3DEt+HSnfuahoIMOzzrQAQi4hElIZlMdM5pugHnpjJiwgnbT3yY5lh5IcxkGt4wG2wYExFrefFva0U2A8Q9fBTW0pIW5ZsihaMky7JoQbSpQR1O9pXNXlprXIlotXPxM0CTF7sl3fJVQ=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.8) Gecko/20100301 Fedora/3.0.3-1.fc12 Lightning/1.0b2pre Thunderbird/3.0.3
Keir, Jeremy,

Just a rather obvious request that you digitally sign all the published
tgz packages, as well as hg/git tags, so that it was possible to ensure
that the software I download from xen.org (or fetch from Jeremy's GIT)
is authentic. This is especially important for those people who would
like to build (and distribute!) their own products based on Xen.

Hopefully you can start doing this with the upcoming 4.0.0 and 3.4.3
versions of Xen, and the "official" pvops kernels (hopefully there will
be some pvops commit tagged as "official"? I assume from
xen/stale-2.6.32.x?)

Thanks,
joanna.

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel
<Prev in Thread] Current Thread [Next in Thread>