From mboxrd@z Thu Jan 1 00:00:00 1970 From: Pierre Neidhardt Subject: Re: Guix and remote trust Date: Fri, 13 Dec 2019 14:38:46 +0100 Message-ID: <87d0css5uh.fsf@ambrevar.xyz> References: <87eex9r5ay.fsf@ambrevar.xyz> <87h825wkj6.fsf@cbaines.net> <87h824d319.fsf@ambrevar.xyz> <8736doct1z.fsf@ambrevar.xyz> <87d0csbbyh.fsf@ambrevar.xyz> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:470:142:3::10]:59638) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ifl9g-0000qn-0b for help-guix@gnu.org; Fri, 13 Dec 2019 08:38:53 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ifl9e-0003gh-J7 for help-guix@gnu.org; Fri, 13 Dec 2019 08:38:51 -0500 Received: from relay5-d.mail.gandi.net ([217.70.183.197]:51207) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1ifl9e-0003c1-BZ for help-guix@gnu.org; Fri, 13 Dec 2019 08:38:50 -0500 In-Reply-To: <87d0csbbyh.fsf@ambrevar.xyz> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: help-guix-bounces+gcggh-help-guix=m.gmane.org@gnu.org Sender: "Help-Guix" To: zimoun Cc: help-guix --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Pierre Neidhardt writes: > The other way around would work (with root access): build everything on > balaitou, guix publish there, then run "guix challenge" on Aneto. Actually I don't think this works either: if the balaitou remote is compromised, it may very lie about the challenge. I don't know how `guix challenge' works so I may be wrong here. =2D-=20 Pierre Neidhardt https://ambrevar.xyz/ --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEUPM+LlsMPZAEJKvom9z0l6S7zH8FAl3zlGYACgkQm9z0l6S7 zH9BGwf/UhFXSpeQwZSds1lZf/V3ojffzdTuayFRIM4svKLS1qu//yf6I0Pdci6k RCOw4hfZ0M9QAkJ3volNlQ2ufIWmRAXV5nY7mffRHRdlUE2Ey3ZgwmNl98gIR7LX PYG366lpl0hysxxRD2pGTHO/2cKuf0FkYk5g9K2cwfakwn4mPOGeDEk2OYkGMdlS RR2P3vSEOtvOx2dwvbZRaJzgzAAl3s21LEQB4AaRHlZpdcvKeJOtKDNhoG+uZusQ Uqh8cgefBPfkJVB3QCKQBZtYj1zLpe8gQHqbCmHFZzjY49dOs6XFtpQjmMJpBQw/ d4AQU8darzk2c3CSFYGDHgGw7tUWBw== =LDqR -----END PGP SIGNATURE----- --=-=-=--