From eenge@prium.net Mon Nov 10 15:25:05 2003 From: Erik Enge To: clo-devel@common-lisp.net Subject: Re: [clo-devel] Re: Please upload your public GPG key to common-lisp.net Date: Mon, 10 Nov 2003 15:27:41 -0500 Message-ID: <871xsg2cle.fsf@prium.net> In-Reply-To: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============3193877385938948224==" --===============3193877385938948224== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Nikodemus Siivola writes: > Need To Know Basis, of course. As long as you're willing to shoulder > the signing, no-one else needs to know. If you think you need help, > then someone else as well. I don't think I need help but if I get hit by the bus you're out of luck. I think perhaps telling a couple of you will be appropriate. How's this for the website: We want users and developers who download software from this site to have a way of verifying that what they just downloaded is indeed what the author uploaded and that the author who uploaded the software indeed is the author they think he is. This will help in preventing trojaned software to spread. For the user to verify a software package (usually a tarball or a zip file), the author will need to sign said package use his GPG (or