Re: Archive signatures versus message digests

> Why does it matter what Red Hat legal obligations are? I say it once
> again: SHA256 is not there to provide security. GPG might be nice, not
> doing it at the moment, will be done at some point in future.

Excellent. I hope that point of future will come soon !

Yes, excellent. Shell access for developers is craziness, as you noted. 

Developers shall only have the right to upload their tarball along with
its digital signature if the packages are signed by the developers or
otherwise just the tarball over a secure connection if the packages are
going to be signed automatically by a master (the paid sysadmin) on
his/her behalf by a script or periodic process or modified SCP/SFTP
server upon arrival of the tarball.

Developers can just use plain and simple SCP or SFTP and SSH is
completely disabled on the server.

Thanks very much for volunteering your time !

Kind regards,

Guido Trentalancia

