Re: signing commits



On Thu, 2013-08-29 at 09:12 -0400, Colin Walters wrote:

This sort of thing is why for the OSTree core I just went with SSL/TLS;

Although I should further note a model I expect to be widely deployed is
one where only the refs are fetched over https:// from a centralized
pool of servers; from there, you can fetch everything else over plain
http:// from a larger network of mirror servers.  

The clients will validate checksums, so you have integrity.  You don't
have confidentiality, but this is for operating systems with no private
data embedded in them.





[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]