You are not logged in.
Hi,
The [c]tazpkg[/c] scripts download files from the (main) mirror and verify them using [c]md5[/c] method. This is very traditional and I think the packages can be easily modified by 3rd parties.
Is there any feature / plan to support more secure signature and verification methods? (Using GPG for example)
Thanks
Offline
See: /var/lib/tazpkg/packages.md5
Offline
@Hackdorte: Yes I see that file, but I don't think that is enough.
Offline
[ Generated in 0.017 seconds, 7 queries executed - Memory usage: 1.53 MiB (Peak: 1.77 MiB) ]