Signed tags for future petitboot releases
Jeremy Kerr
jk at ozlabs.org
Thu Feb 6 03:19:50 AEDT 2020
Hi Joel,
> Are you able to create signed tags for the petitboot releases you
> make?
Sure, can do! Just for future releases, or would you prefer signed tags
for 1.11 and 1.12?
> More importantly, someone is able to check that someone in possession
> of your key created the tag.
Yep, makes sense.
However, my only (non-expired) key at present is super old, and only
1024-bit; looks like I'll need a new one. However, you won't have a
trust path to that. Do I need to fly over to Adelaide for a signing
party? :D
Cheers,
Actual Jeremy
More information about the Petitboot
mailing list