From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ricardo Wurmus Subject: bug#27437: Source downloader accepts X.509 certificate for incorrect domain Date: Thu, 27 Jul 2017 21:34:29 +0200 Message-ID: <87r2x165dm.fsf@elephly.net> References: <20170621061752.GA32412@jasmine.lan> <87lgolipi0.fsf@gnu.org> <87injohwac.fsf@netris.org> <87o9tf1ytl.fsf@elephly.net> <20170623032401.GA13366@jasmine.lan> <87fuer9n6d.fsf@elephly.net> <87k22u3vx2.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46892) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1daoYs-0004rJ-QP for bug-guix@gnu.org; Thu, 27 Jul 2017 15:35:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1daoYo-0003yy-NA for bug-guix@gnu.org; Thu, 27 Jul 2017 15:35:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:56269) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1daoYo-0003yR-Kc for bug-guix@gnu.org; Thu, 27 Jul 2017 15:35:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1daoYo-0003za-Ey for bug-guix@gnu.org; Thu, 27 Jul 2017 15:35:02 -0400 Sender: "Debbugs-submit" Resent-To: bug-guix@gnu.org Resent-Message-ID: In-reply-to: <87k22u3vx2.fsf@gnu.org> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 27437-done@debbugs.gnu.org Ludovic Courtès writes: > Ricardo Wurmus skribis: > >>>From 44b8f1c04713d11601d964ecfbe2fc248a15e7c0 Mon Sep 17 00:00:00 2001 >> From: Ricardo Wurmus >> Date: Fri, 23 Jun 2017 09:24:58 +0200 >> Subject: [PATCH] doc: Encourage signature verification. >> >> * doc/contributing.texi (Submitting Patches): Remind contributors to verify >> cryptographic signatures. >> --- >> doc/contributing.texi | 6 ++++++ >> 1 file changed, 6 insertions(+) >> >> diff --git a/doc/contributing.texi b/doc/contributing.texi >> index 925c584e4..0073f2451 100644 >> --- a/doc/contributing.texi >> +++ b/doc/contributing.texi >> @@ -334,6 +334,12 @@ updates for a given software package in a single place and have them >> affect the whole system---something that bundled copies prevent. >> >> @item >> +If the authors of the packaged software provide a cryptographic >> +signature for the release tarball, make an effort to verify the >> +authenticity of the archive. For a detached GPG signature file this >> +would be done with the @code{gpg --verify} command. > > I would make it the very first item of the check list. > > If that’s fine with you, please push and maybe close the bug! Looks like I’ve already pushed this a while back. I’ll move it up to the top of the list. (And I’m closing this bug.) -- Ricardo GPG: BCA6 89B6 3655 3801 C3C6 2150 197A 5888 235F ACAC https://elephly.net