Received: from spf3.us4.outblaze.com (spf3.us4.outblaze.com [205.158.62.25]) by sdf.lonestar.org (8.12.10/8.12.10) with ESMTP id iAGJjqkj020502 for ; Tue, 16 Nov 2004 19:45:52 GMT Received: from lists.gnu.org (lists.gnu.org [199.232.76.165]) by spf3.us4.outblaze.com (Postfix) with ESMTP id 02C1353805 for ; Tue, 16 Nov 2004 19:45:40 +0000 (GMT) Received: from localhost ([127.0.0.1] helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.33) id 1CU9PW-0006BW-C1 for migo@homemail.com; Tue, 16 Nov 2004 14:54:42 -0500 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.33) id 1CU9P5-0006BP-KX for gnu-arch-users@gnu.org; Tue, 16 Nov 2004 14:54:15 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.33) id 1CU9P5-0006BC-7E for gnu-arch-users@gnu.org; Tue, 16 Nov 2004 14:54:15 -0500 Received: from [199.232.76.173] (helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.33) id 1CU9P5-0006B9-3s for gnu-arch-users@gnu.org; Tue, 16 Nov 2004 14:54:15 -0500 Received: from [212.71.168.94] (helo=vagabond.light.src) by monty-python.gnu.org with esmtp (Exim 4.34) id 1CU9Fn-00021H-CW for gnu-arch-users@gnu.org; Tue, 16 Nov 2004 14:44:39 -0500 Received: from bulb by vagabond.light.src with local (Exim 3.36 #1 (Debian)) id 1CU9FW-0000fn-00; Tue, 16 Nov 2004 20:44:22 +0100 Date: Tue, 16 Nov 2004 20:44:22 +0100 From: Jan Hudec To: Karel Gardas Subject: Re: [Gnu-arch-users] Re: darcs vs tla Message-ID: <20041116194422.GA9828@vagabond> References: Mime-Version: 1.0 In-Reply-To: User-Agent: Mutt/1.5.6+20040907i Cc: gnu-arch-users@gnu.org, lode.leroy@advalvas.be, jeremy.shaw@linspireinc.com, Dustin Sallings X-BeenThere: gnu-arch-users@gnu.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: a discussion list for all things arch-ish List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: multipart/mixed; boundary="===============1879065464==" Sender: gnu-arch-users-bounces+migo=homemail.com@gnu.org Errors-To: gnu-arch-users-bounces+migo=homemail.com@gnu.org Status: RO Content-Length: 3211 Lines: 102 --===============1879065464== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="ew6BAiZeqk4r7MaW" Content-Disposition: inline --ew6BAiZeqk4r7MaW Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Nov 15, 2004 at 22:31:09 +0100, Karel Gardas wrote: > On Mon, 15 Nov 2004, Dustin Sallings wrote: >=20 > > > > On Nov 15, 2004, at 3:45, Karel Gardas wrote: > > > > > Darcs' cons: > > > > > > - darcs does not support patch signing (showstopper for me) > > > > That's not *exactly* true. darcs does support having signed patches > > on send when using the following flags: >=20 > You are right! I've completely omited this since in comparison with tla's > support it looks quite weak. i.e. tla support signing/verification for > every transport AFAIK, at least I'm using sftp/http and > signing/verification works well for them. So I should rather rewrite my > original statement to: >=20 > - darcs does not support patch signing/verification except simple > email-based transport method (showstopper for me) Arch does not support signing/verification for transport -- it supports it for STORAGE. That's the key point. The signatures are stored and can be validated at any point in future. Eg. after a security accident. > > While the signature isn't recorded in the patch itself or your working > > tree (although the patch name includes the sha1), it can be validated > > if you keep the source of the patch (i.e. an email archive if you're > > using email for transport). >=20 > Yes, I will probably need to go to darcs mailing list to find out why > signatures are not part of patch and why it does not verify automatically > when they are presented (while using apply command), i.e. currently it is > quite easy to apply unverified patches just by mistake IMHO. >=20 > Anyway thanks for the hint! >=20 > Karel > -- > Karel Gardas kgardas@objectsecurity.com > ObjectSecurity Ltd. http://www.objectsecurity.com >=20 >=20 >=20 >=20 > _______________________________________________ > Gnu-arch-users mailing list > Gnu-arch-users@gnu.org > http://lists.gnu.org/mailman/listinfo/gnu-arch-users >=20 > GNU arch home page: > http://savannah.gnu.org/projects/gnu-arch/ >=20 ---------------------------------------------------------------------------= ---- Jan 'Bulb' Hudec --ew6BAiZeqk4r7MaW Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFBmliWRel1vVwhjGURAp2fAKDFDKcVFZG+yRxPxAXl0Wtxt15UAQCeI3Vr FDi1xRUbM3nflxJKdvxpZIQ= =dTHa -----END PGP SIGNATURE----- --ew6BAiZeqk4r7MaW-- --===============1879065464== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Gnu-arch-users mailing list Gnu-arch-users@gnu.org http://lists.gnu.org/mailman/listinfo/gnu-arch-users GNU arch home page: http://savannah.gnu.org/projects/gnu-arch/ --===============1879065464==--