From mboxrd@z Thu Jan 1 00:00:00 1970 From: Werner Koch Subject: bug#22883: Trustable "guix pull" Date: Sun, 05 Jun 2016 09:51:45 +0200 Message-ID: <877fe4hy3y.fsf@wheatstone.g10code.de> References: <87io14sqoa.fsf@dustycloud.org> <87fustj59o.fsf@wheatstone.g10code.de> <874m98vbcg.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:60841) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1b9Svi-0006T0-EM for bug-guix@gnu.org; Sun, 05 Jun 2016 03:57:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1b9Sve-0007BR-W8 for bug-guix@gnu.org; Sun, 05 Jun 2016 03:57:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:42526) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1b9Sve-0007BM-Sz for bug-guix@gnu.org; Sun, 05 Jun 2016 03:57:02 -0400 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <874m98vbcg.fsf@gnu.org> ("Ludovic =?UTF-8?Q?Court=C3=A8s?="'s message of "Sun, 05 Jun 2016 00:27:27 +0200") List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 22883@debbugs.gnu.org, Justus Winter , neal@walfield.org On Sun, 5 Jun 2016 00:27, ludo@gnu.org said: > cannot or shouldn=E2=80=99t try to guess what=E2=80=99s =E2=80=9Cbest=E2= =80=9D, IMO. So in this case, > we keep the default names, =E2=80=98gpg2=E2=80=99 and =E2=80=98gpgv2=E2= =80=99. > > Do you think we should rename those files? Given that Guix is a new distro you should really try to get rid of 1.4 and only use 2.1. For Windows we use the name "gpg" for a long time now and there is a configure option --enable-gpg2-is-gpg to make it easier. > We sign commits and it=E2=80=99s wonderful; now all we need is tools to a= ctually > use those signatures to authenticate checkouts. :-) Right - Although I sign my commits,e other GnuPG hackers don't do it, and thus for me there is no strong need to verify the commits. But we should have these tools. Shalom-Salam, Werner --=20 Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz. /* EFH in Erkrath: https://alt-hochdahl.de/haus */