Reflections on Trusting Trust

Colin Percival cperciva at freebsd.org
Tue Nov 29 23:45:41 GMT 2005


Kris Kennaway wrote:
> Also, pkg_sign(1) has existed for a long time, but needs the support
> infrastructure to make it usable.

Last I heard, pkg_sign(1) became non-functional when we changed from
gzipped tarballs to bzip2ed tarballs for packages.

Colin Percival


More information about the freebsd-security mailing list