WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] Xen signing and wget

To: Keir Fraser <keir.fraser@xxxxxxxxxxxxx>
Subject: Re: [Xen-devel] Xen signing and wget
From: Joanna Rutkowska <joanna@xxxxxxxxxxxxxxxxxxxxxx>
Date: Tue, 06 Jul 2010 17:27:24 +0200
Cc: "xen-devel@xxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxx>
Delivery-date: Tue, 06 Jul 2010 08:27:37 -0700
Dkim-signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=messagingengine.com; h=message-id:date:from:mime-version:to:cc:subject:references:in-reply-to:content-type; s=smtpout; bh=kJmuZkAE5Aw2nAneajzLJruHd6c=; b=ZV6MX4CotTTwtxN/Qoqhl5r5SdUISFOm9buTAoMUPKWlq+SLuo91su2OQgnkakKyw3ijYn3sMrmPhzGeCM0PXig5QOhhVchjCxuy3m2FWwqddYRRf1Kfnj9AWFPURD/DPgE/ZlZ/uGMmDZ63kpHIp+3drsv6mnhfV6VtpsYfsyg=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <C8590952.1980C%keir.fraser@xxxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <C8590952.1980C%keir.fraser@xxxxxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.10) Gecko/20100621 Fedora/3.0.5-1.fc13 Lightning/1.0b2pre Thunderbird/3.0.5
On 07/06/10 17:24, Keir Fraser wrote:
> On 06/07/2010 16:23, "Joanna Rutkowska" <joanna@xxxxxxxxxxxxxxxxxxxxxx>
> wrote:
> 
>>> We download tarballs from http://xenbits.xensource.com/xen-extfiles rather
>>> than random 3rd party sites. And qemu from our very own git repository also
>>> on xenbits.
>>>
>> But you use plaintext connection, which, in security, means random code.
>> I think we have already went through this last time when discussing the
>> signing process for Xen ;)
> 
> Okay, then make a patch, including hashes for our current collection of
> downloads.

I'm not a Xen developer. I do not sign your tarballs...

joanna.

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel