| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
| |
Discussed with: bapt
MFC after: instantly (preparing EN)
|
|
|
|
| |
MFC after: 2 days
|
|
|
|
|
| |
Approved by: bapt
MFC after: 2 days
|
|
|
|
|
|
|
| |
fingerprint has an uploaded signature on all mirrors.
Approved by: bapt
MFC after: 2 days
|
|
|
|
|
| |
Requested by: secteam (cperciva, des)
Approved by: bapt
|
|
|
|
|
|
| |
not receive the signature until later this week.
Approved by: bapt
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
If the pkg.conf is configured with SIGNATURE_TYPE: FINGERPRINTS,
and FINGERPRINTS: /etc/keys/pkg then a pkg.sig file is fetched along
with pkg.txz. The signature contains the signature provided by the
signing server, and the public key. The .sig is the exact output
from the signing server in the following format:
SIGNATURE
<openssl signed>
CERT
<rsa public key>
END
The signature is verified with the following logic:
- If the .sig file is missing, it fails.
- If the .sig doesn't validate, it fails.
- If the public key in the .sig is not in the known trusted fingerprints,
it fails.
- If the public key is in the revoked key list, it fails.
Approved by: bapt
MFC after: 2 days
Discussed by: bapt with des, jonathan, gavin
|
|
For now only /etc/pkg/FreeBSD.conf is supported. Its style is:
Repo: {
URL: "...",
MIRROR_TYPE: "...",
...
}
The configuration will be read from /usr/local/etc/pkg.conf if exists,
otherwise /etc/pkg/FreeBSD.conf
Approved by: bapt
MFC after: 2 days
|